Summary
When a request to /api/rest/... fails on the server side, the client does not receive the error status. It receives
200 OK with Content-Type: text/html and the body of the web application's index.html. A client that checks the
status code treats the failure as a success; a client that parses JSON fails with an unrelated parse error.
An unknown element id is answered with 404 and an empty body, as expected; the problem is with errors raised while
handling the request.
Environment
- SysON v2026.9.0 and v2026.9.2 (Docker images
eclipsesyson/syson:v2026.9.0 / v2026.9.2, linux/amd64); also seen on v2026.5.0
- Requests sent directly to the container's published port on
localhost, no proxy in between
Reproduction
With any existing project {p}:
GET /api/rest/projects/{p}/commits/{p}/elements/not-a-uuid
Accept: application/json
Response:
Status: 200
Content-Type: text/html
<!DOCTYPE html>
<html lang="en">
<head>
...
<title>SysON</title>
Server log for the same request:
WARN 1 --- [nio-8080-exec-3] .w.s.m.s.DefaultHandlerExceptionResolver : Resolved [org.springframework.web.method.annotation.MethodArgumentTypeMismatchException: Method parameter 'elementId': Failed to convert value of type 'java.lang.String' to required type 'java.util.UUID'; Invalid UUID string: not-a-uuid]
Spring's DefaultHandlerExceptionResolver handled the exception (it maps MethodArgumentTypeMismatchException to
400 Bad Request), but the response that reached the client is 200 with the HTML page.
In v2026.5.0 the same happened for a NullPointerException in SysMLv2JsonSerializer.serialize (line 51) while
serializing a FlowDefinition (that NPE is fixed in v2026.9.0): the log showed
Request processing failed: java.lang.NullPointerException, and the client received 200 with index.html.
Also in v2026.5.0, a malformed multipart request to /api/graphql/upload (a map entry given as an array) was logged
as a JsonNodeException and answered the same way, so this may not be specific to the REST API.
Expected
The error status (400, 500, …), as 404 already is. A JSON error body would help, but the status alone would be
enough for a client to tell the failure apart.
Cause
Not located. The body is the page the application serves for its front-end routes, so the replacement may happen in
Sirius Web rather than in SysON's REST module.
Summary
When a request to
/api/rest/...fails on the server side, the client does not receive the error status. It receives200 OKwithContent-Type: text/htmland the body of the web application'sindex.html. A client that checks thestatus code treats the failure as a success; a client that parses JSON fails with an unrelated parse error.
An unknown element id is answered with
404and an empty body, as expected; the problem is with errors raised whilehandling the request.
Environment
eclipsesyson/syson:v2026.9.0/v2026.9.2,linux/amd64); also seen on v2026.5.0localhost, no proxy in betweenReproduction
With any existing project
{p}:Response:
Server log for the same request:
Spring's
DefaultHandlerExceptionResolverhandled the exception (it mapsMethodArgumentTypeMismatchExceptionto400 Bad Request), but the response that reached the client is200with the HTML page.In v2026.5.0 the same happened for a
NullPointerExceptioninSysMLv2JsonSerializer.serialize(line 51) whileserializing a
FlowDefinition(that NPE is fixed in v2026.9.0): the log showedRequest processing failed: java.lang.NullPointerException, and the client received200withindex.html.Also in v2026.5.0, a malformed multipart request to
/api/graphql/upload(amapentry given as an array) was loggedas a
JsonNodeExceptionand answered the same way, so this may not be specific to the REST API.Expected
The error status (
400,500, …), as404already is. A JSON error body would help, but the status alone would beenough for a client to tell the failure apart.
Cause
Not located. The body is the page the application serves for its front-end routes, so the replacement may happen in
Sirius Web rather than in SysON's REST module.