Repository navigation
Refuse a cursor value that breaks the kind declared for its key. - #11
Merged
Merged
Conversation
A cursor round-trips through the client, and Criteria::fromQuery only checked that it decodes into one value per sort order. A forged value reached the store through the column binding, so a cursor carrying a non-UUID id answered 500 wherever the id is bound through UUID_TO_BIN. A Schema now declares the kind of a cursor key with cursorKey, the new UUID kind joins the others, and fromQuery rejects a value outside its declared kind with CursorIsInvalid. A field without a declared kind is not checked, so existing schemas behave as before.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Criteria::fromQuery rejected a cursor that does not decode into one value per sort order, and accepted any scalar it decoded into. Those values reach the store through the column binding, so a cursor whose id was forged into anything other than a UUID answered 500 wherever the id is bound through UUID_TO_BIN, instead of 422. A Schema now declares the kind a cursor key must match through cursorKey, the new UUID kind joins STRING, INTEGER and DATETIME, and fromQuery rejects a value outside its declared kind with CursorIsInvalid, at the boundary every consumer already wraps. A field without a declared kind is not checked, so existing schemas behave as before, and a consumer closes the gap by declaring the kind of its cursor keys.
Summary
What this pull request does.
Related issue
Closes #...
Checklist
make reviewpasses.make testspasses.