Skip to content

fix(sdk): encode sandbox metadata filters once - #1940

Closed
DevChiniwala wants to merge 1 commit into
e2b-dev:mainfrom
DevChiniwala:fix/sandbox-metadata-filter-encoding
Closed

DevChiniwala wants to merge 1 commit into
e2b-dev:mainfrom
DevChiniwala:fix/sandbox-metadata-filter-encoding

Conversation

@DevChiniwala

@DevChiniwala DevChiniwala commented Oct 4, 2026 •

Copy link
Copy Markdown

Problem

The OpenAPI contract says each metadata filter key and value must be URL-encoded (sandbox list parameter). Both SDKs encoded each component and then passed them through another encoder while assembling the inner metadata query string. For example, a filter containing a space or & arrived with its percent escapes encoded again, so the API could not match the original metadata.

Fix

Build the inner query from individually encoded keys and values, joining pairs with literal & and = separators. The Python sync and async SDKs use the same helper.

Usage

const page = await Sandbox.list({
  query: { metadata: { 'team name': 'hello & world' } },
}).nextItems()

Regression coverage

Mocked request tests verify the metadata query value after HTTP query parsing. Coverage includes multiple filters, spaces, Unicode, slashes, ampersands, equals signs, and percent signs across JavaScript, Python sync, and Python async.

Validation

  • JS unit tests: 22 passed, including the new request serialization regression
  • JS build: passed
  • JS lint: passed with two pre-existing require-yield warnings in watchHandle.test.ts
  • JS Prettier check: passed
  • Python regression tests: 2 passed
  • Python ruff check ., ruff format --check ., and ty check: passed
  • pnpm changeset status: passed

Compatibility

No public signatures changed. Plain metadata filters remain unchanged; filters containing URL-encoded characters now arrive in the format specified by the API.

Changeset

Patch releases for e2b and @e2b/python-sdk.

Copilot AI balanced review requested due to automatic review settings October 4, 2026 12:58
@cla-bot

cla-bot Bot commented Oct 4, 2026

Copy link
Copy Markdown

We require contributors to sign our Contributor License Agreement, and we don't have @DevChiniwala on file. You can sign our CLA at https://e2b.dev/docs/cla . Once you've signed, post a comment here that says '@cla-bot check'

@changeset-bot

changeset-bot Bot commented Oct 4, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 046c6de

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
Name Type
e2b Patch
@e2b/python-sdk Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TASTE.md review: no violations — checked T-1 (JS encodeURIComponent and Python quote(safe="!~*'()-._") escape the same characters), T-2 (one shared helper in e2b/sandbox/ used by sync and async), T-52 (no new client-side validation) and T-3/T-10 (no public signature changes); 0 inline comments.

@DevChiniwala

Copy link
Copy Markdown
Author

@cla-bot check

@cla-bot

cla-bot Bot commented Oct 4, 2026

Copy link
Copy Markdown

We require contributors to sign our Contributor License Agreement, and we don't have @DevChiniwala on file. You can sign our CLA at https://e2b.dev/docs/cla . Once you've signed, post a comment here that says '@cla-bot check'

@cla-bot

cla-bot Bot commented Oct 4, 2026

Copy link
Copy Markdown

The cla-bot has been summoned, and re-checked this pull request!

@mishushakov

Copy link
Copy Markdown
Member

Hey, the PR is incorrect, closing.

@mishushakov mishushakov closed this Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants