Skip to content

Refuse a cursor value that breaks the kind declared for its key. - #11

Merged
gustavofreze merged 2 commits into
mainfrom
feature/declared-cursor-key-kinds
Oct 7, 2026
Merged

gustavofreze merged 2 commits into
mainfrom
feature/declared-cursor-key-kinds

Conversation

@gustavofreze

Copy link
Copy Markdown
Member

Criteria::fromQuery rejected a cursor that does not decode into one value per sort order, and accepted any scalar it decoded into. Those values reach the store through the column binding, so a cursor whose id was forged into anything other than a UUID answered 500 wherever the id is bound through UUID_TO_BIN, instead of 422. A Schema now declares the kind a cursor key must match through cursorKey, the new UUID kind joins STRING, INTEGER and DATETIME, and fromQuery rejects a value outside its declared kind with CursorIsInvalid, at the boundary every consumer already wraps. A field without a declared kind is not checked, so existing schemas behave as before, and a consumer closes the gap by declaring the kind of its cursor keys.

Please follow the contributing guidelines.

Summary

What this pull request does.

Related issue

Closes #...

Checklist

  • Tests added or updated.
  • Documentation updated when applicable.
  • make review passes.
  • make tests passes.

A cursor round-trips through the client, and Criteria::fromQuery only
checked that it decodes into one value per sort order. A forged value
reached the store through the column binding, so a cursor carrying a
non-UUID id answered 500 wherever the id is bound through UUID_TO_BIN.
A Schema now declares the kind of a cursor key with cursorKey, the new
UUID kind joins the others, and fromQuery rejects a value outside its
declared kind with CursorIsInvalid. A field without a declared kind is
not checked, so existing schemas behave as before.
@gustavofreze gustavofreze self-assigned this Oct 7, 2026
@gustavofreze
gustavofreze merged commit bc1cd0f into main Oct 7, 2026
5 checks passed
@gustavofreze
gustavofreze deleted the feature/declared-cursor-key-kinds branch October 7, 2026 00:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant