View Issue Details

IDProjectCategoryView StatusLast Update
0037443mantisbtcustom fieldspublic2026-10-08 12:38
Reportermb-kh Assigned To 
PrioritynormalSeveritycrashReproducibilityalways
Status confirmedResolutionopen 
Product Version2.28.4 
Target Version2.29.0 
Summary0037443: Issue created via REST API with too long value for custom field fails in the middle of operation with 500 error
Description

When you create an issue via REST API with a custom field (String type) and send value which is too long, more than 255 characters, it creates an issue but fails during 'INSERT INTO mantis_custom_field_string_table [...]'. Exception is thrown from database that data is too long for column 'value'.
Issue exists but without all provided values for custom fields and 500 response code is returned.

We were able to find a root cause quite quickly because we found deprecation message in logs:
Unhandled deprecation warning in /var/www/mantis/core/classes/DbQuery.class.php line 298: 'Passing E_USER_ERROR to trigger_error() is deprecated since 8.4, throw an exception or call exit with a string message instead'.

It fails in:

if( !$this->db_result ) { db_error( $this->db_query_string ); trigger_error( ERROR_DB_QUERY_FAILED, ERROR ); $this->db_result = false; }

Steps To Reproduce
  1. Attach a custom field to project, String type.
  2. Create an issue via REST API and in request body send custom field value longer than 255 characters.
  3. Request fails with 500.
Additional Information

PHP 8.4
MariaDB 11.8.6

TagsNo tags attached.

Activities

dregad

dregad

2026-10-08 12:38

developer   ~0071495

Behavior is confirmed, also on master branch (although there the deprecation warning has been fixed and an exception is thrown so the API does return HTTP 500 and not 200, but the issue still gets created without the custom field data).

Problem also occurs when updating an issue (PATCH /issues/{id} endpoint), as well as from the GUI with a crafted POST request.