{"data":{"id":"magento2-38282","source":"github-pr","sourceRef":"magento/magento2#38282","title":"Internal Server Error in `/V1/order/{orderId}/ship` API Endpoint","pr":{"number":38282,"url":"https://github.com/magento/magento2/pull/38282","author":"rogerdz","mergedAt":"2025-09-15T06:18:45Z","mergeCommit":"74f5a2fe567949974637b9eff7c05e91c038ae2b","headCommit":"04a191bc07fd3120153d599d0ccf96ef0a0d4934","baseRef":"2.4-develop","diffSha256":"3901069712b5d260b17ae9e87daa4e2614ce3bd411f158166fbb342867374db5"},"issues":[{"number":35931,"url":"https://github.com/magento/magento2/issues/35931","title":"Internal Server Error in `/V1/order/{orderId}/ship` API Endpoint","labels":["Area: APIs","Component: Api","Issue: Confirmed","Priority: P2","Progress: PR in progress","Progress: done","Reported on 2.4.x","Reproduced on 2.4.x"],"kind":"human"}],"fixedIn":"2.4.9","containingTags":["2.4.9"],"reportedOn":null,"codeMatch":{"2.4.6":"clean","2.4.6-p1":"clean","2.4.6-p2":"clean","2.4.6-p3":"clean","2.4.6-p4":"clean","2.4.6-p5":"clean","2.4.6-p6":"clean","2.4.6-p7":"clean","2.4.6-p8":"clean","2.4.6-p9":"clean","2.4.6-p10":"clean","2.4.6-p11":"clean","2.4.6-p12":"clean","2.4.6-p13":"clean","2.4.6-p14":"clean","2.4.6-p15":"clean","2.4.7":"clean","2.4.7-p1":"clean","2.4.7-p2":"clean","2.4.7-p3":"clean","2.4.7-p4":"clean","2.4.7-p5":"clean","2.4.7-p6":"clean","2.4.7-p7":"clean","2.4.7-p8":"clean","2.4.7-p9":"clean","2.4.7-p10":"clean","2.4.8":"clean","2.4.8-p1":"clean","2.4.8-p2":"clean","2.4.8-p3":"clean","2.4.8-p4":"clean","2.4.8-p5":"clean","2.4.9":"conflict"},"affectedVersions":["2.4.6","2.4.6-p1","2.4.6-p2","2.4.6-p3","2.4.6-p4","2.4.6-p5","2.4.6-p6","2.4.6-p7","2.4.6-p8","2.4.6-p9","2.4.6-p10","2.4.6-p11","2.4.6-p12","2.4.6-p13","2.4.6-p14","2.4.6-p15","2.4.7","2.4.7-p1","2.4.7-p2","2.4.7-p3","2.4.7-p4","2.4.7-p5","2.4.7-p6","2.4.7-p7","2.4.7-p8","2.4.7-p9","2.4.7-p10","2.4.8","2.4.8-p1","2.4.8-p2","2.4.8-p3","2.4.8-p4","2.4.8-p5"],"components":["magento/module-webapi"],"files":[{"path":"app/code/Magento/Webapi/Controller/Rest/SynchronousRequestProcessor.php","change":"modified","package":"magento/module-webapi"}],"stripped":{"tests":["dev/tests/api-functional/testsuite/Magento/Sales/Service/V1/ShipOrderTest.php"],"docs":[],"outsideCode":[]},"linesChanged":19,"mergeBatched":false,"excluded":null,"sections":{"description":"Returns a 500 status code from a null TypeError .","stepsToReproduce":"1. Retrieve auth token from the admin endpoint /V1/integration/admin/\n2. Request endpoint: POST : //yourstore/rest/V1/order/{orderId}/ship\nPayload:\n_{\n  \"items\": \"[]\"\n}_\n\nOther below APi's also got effected and getting similar error in logs:\n1. POST request to /V1/inventory/stock-source-links with payload:\n_{\"links\": \"[]\"}_ \n2. POST request to /rest/V1/inventory/source-items with payload:\n_{\"sourceItems\": \"\\\\[]\\\\\"}_\n3. POST request to //V1/inventory/low-quantity-notification with payload:\n_{\"sourceItemConfigurations\": \"\"}_\n4. POST request to /rest/V1/inventory/stock-source-links-delete with payload:\n_{\"links\": \"\\\\[]\\\\\"}_","expectedResult":"Returns a 400 error as the request is malformed.","actualResult":"Returns a 500 status code from a null TypeError .","source":"issue"},"signatures":["Returns a 500 status code from a null TypeError .","[2022-08-01T12:54:49.463557+00:00] main.CRITICAL: TypeError: Magento\\Sales\\Model\\ShipOrder::execute(): Argument ($items) must be of type array, null given"],"labels":{"area":["APIs"],"component":["Api"],"priority":"P2","severity":null,"reportedOn":["2.4.x"]},"categories":["Web API"],"triage":{"model":"@cf/cloudflare/clef","requestHash":"e8cfc07f511f73a3599ef92eb2d856b5688a81f677afa19ad6486d2d4c9cdb27","isBugfix":0.9683,"changeKind":{"choice":"bugfix","probabilities":{"bugfix":0.9575,"feature":0.0062,"refactor":0.0162,"tests_only":0.0113,"docs_only":0.0039,"dependency":0.0049},"confidence":0.9006},"scope":{"score":0.835,"probabilities":{"0":0.3634,"1":0.4381,"2":0.1985},"confidence":0.0451},"risk":{"score":0.3892,"probabilities":{"0":0.6782,"1":0.2544,"2":0.0674},"confidence":0.2938},"area":{"choice":"graphql_api","probabilities":{"catalog":0.0109,"checkout":0.0631,"customer":0.0039,"admin":0.0095,"graphql_api":0.8606,"framework":0.0355,"frontend":0.0033,"other":0.0132},"confidence":0.71},"securityRelevant":0.0197,"reportedVersion":{"choice":"unspecified","probabilities":{"2.4.0":0.032,"2.4.0-p1":0.0118,"2.4.1":0.0071,"2.4.1-p1":0.0066,"2.4.2":0.0079,"2.4.2-p1":0.0113,"2.4.2-p2":0.0116,"2.4.3":0.0152,"2.4.3-p1":0.018,"2.4.3-p2":0.0152,"2.4.3-p3":0.0081,"2.4.4":0.0199,"2.4.4-p1":0.0188,"2.4.4-p10":0.0071,"2.4.4-p11":0.0103,"2.4.4-p12":0.0074,"2.4.4-p13":0.0063,"2.4.4-p14":0.0085,"2.4.4-p15":0.0062,"2.4.4-p16":0.007,"2.4.4-p17":0.0058,"2.4.4-p18":0.0054,"2.4.4-p2":0.0046,"2.4.4-p3":0.0047,"2.4.4-p4":0.0045,"2.4.4-p5":0.0053,"2.4.4-p6":0.0055,"2.4.4-p7":0.0055,"2.4.4-p8":0.0047,"2.4.4-p9":0.0041,"2.4.5":0.0106,"2.4.5-p1":0.0085,"2.4.5-p10":0.0056,"2.4.5-p11":0.0085,"2.4.5-p12":0.0073,"2.4.5-p13":0.0064,"2.4.5-p14":0.0075,"2.4.5-p15":0.0059,"2.4.5-p16":0.0053,"2.4.5-p17":0.0053,"2.4.5-p2":0.0035,"2.4.5-p3":0.005,"2.4.5-p4":0.0051,"2.4.5-p5":0.0047,"2.4.5-p6":0.0056,"2.4.5-p7":0.0051,"2.4.5-p8":0.0044,"2.4.5-p9":0.0031,"2.4.6":0.0171,"2.4.6-p1":0.0153,"2.4.6-p10":0.0078,"2.4.6-p11":0.0107,"2.4.6-p12":0.0079,"2.4.6-p13":0.0087,"2.4.6-p14":0.0074,"2.4.6-p15":0.0058,"2.4.6-p2":0.0038,"2.4.6-p3":0.0061,"2.4.6-p4":0.009,"2.4.6-p5":0.0075,"2.4.6-p6":0.0067,"2.4.6-p7":0.0059,"2.4.6-p8":0.005,"2.4.6-p9":0.0038,"2.4.7":0.0126,"2.4.7-p1":0.0118,"2.4.7-p10":0.0069,"2.4.7-p2":0.0069,"2.4.7-p3":0.0108,"2.4.7-p4":0.0121,"2.4.7-p5":0.0105,"2.4.7-p6":0.0118,"2.4.7-p7":0.0081,"2.4.7-p8":0.0082,"2.4.7-p9":0.0046,"2.4.8":0.0109,"2.4.8-p1":0.0102,"2.4.8-p2":0.0119,"2.4.8-p3":0.011,"2.4.8-p4":0.0126,"2.4.8-p5":0.0106,"2.4.9":0.01,"unspecified":0.2962},"confidence":0.0844},"backportWorthy":{"score":1.4258,"probabilities":{"0":0.1473,"1":0.2797,"2":0.573},"confidence":0.1424}},"curated":{"title":"Fixes the 500 error on POST /V1/order/{orderId}/ship when items is not an array","description":"A malformed payload, such as one on POST /V1/order/{orderId}/ship, gave a TypeError and a 500 status code. SynchronousRequestProcessor now has a try/catch on the service call that does throw a WebapiException on a TypeError, for all REST requests that use that processor.","categories":["Web API"],"author":"claude-code/opus-5.5","date":"2026-10-06","reviewedBy":null},"tests":{"2.4.8-p5":{"before":"not-runnable","after":"error","adapted":false,"runAt":"2026-10-06T10:07:28.592Z","releaseCommit":"870a22c63d9d9b68fa3297962e2d5d5841115814","suites":{"api-functional":{"before":"not-runnable","after":"error","runAt":"2026-10-06T10:07:28.592Z"}}},"2.4.7-p10":{"before":"not-runnable","after":"error","adapted":false,"runAt":"2026-10-06T10:57:26.964Z","releaseCommit":"72561bf80652f57cc642a03e2c9a51d74a285b14","suites":{"api-functional":{"before":"not-runnable","after":"error","runAt":"2026-10-06T10:57:26.964Z"}}}}},"_documentation":"https://magento.watch/api","_description":"Upstream fix magento2-38282 details"}