Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

What is the appropriate HTTP status code for a null or missing object attribute?

Let's say we have an API with a route /foo/<id> that represents an instance of an object like this:

class Foo:
    bar: Optional[Bar]
    name: str
    ...

class Bar:
    ...

(Example in Python just because it's convenient, this is about the HTTP layer rather than the application logic.)

We want to expose full serialized Foo instances (which may have many other attributes) under /foo/<id>, but, for the sake of efficiency, we also want to expose /foo/<id>/bar to give us just the .bar attribute of the given Foo.

It feels strange to me to use 404 as the status response when bar is None here, since that's the same status code you'd get if you requested some arbitrarily incorrect route like /random/gibberish, too; if we were to have automatic handling of 404 status in our client-side layer, it would be misinterpreting this with likely explanations such as "we forgot to log in" or "the client-side URL routing was wrong".

However, 200 with a response-body of null (if we're serializing using JSON) feels odd as well, because the presence or absence of the entity at the given endpoint is usually communicated via a status rather than in-line in the body. Would 204 with an empty response-body be the right thing to say here? Is a 404 the right way to go, and if so, what's the right way for the server to communicate nuances like "but that was a totally expected and correct route" or "actually the foo-ID you specified was incorrect, this isn't missing because the attribute was un-set".

What are the advantages and disadvantages of representing the missing-ness of this attribute in different ways?

like image 769
Glyph Avatar asked Oct 24 '25 04:10

Glyph


2 Answers

I wonder if you could more clearly articulate why a 200 with a null response body is odd. I think it communicates exactly what you want, as long as you're not trying to differentiate between a given Foo not having a bar (e.g. Foo.has_key?(bar)) and Foo having a bar explicitly set to null.

like image 109
jayofdoom Avatar answered Oct 26 '25 05:10

jayofdoom


Of 404, https://developer.mozilla.com says,

In an API, this can also mean that the endpoint is valid but the resource itself does not exist.

so I think it's acceptable. 204 doesn't strike me as particularly outlandish in this situation, but is more commonly associated (IME, at least) with DELETEs (and occasionally PUTs/POSTs that don't return results.)

like image 32
swizzard Avatar answered Oct 26 '25 05:10

swizzard