# Tooling and hardening: request validation and core test coverage - The server now validates `positiveIntParam` and `optionalDateParam` inputs instead of trusting query strings — malformed paging/date parameters return a clean 400 rather than leaking into SQL or arithmetic. - Core gained dedicated unit tests for `CappedTextBuffer` and `ToolCallIdAllocator`, two small pure modules that previously had no direct coverage.