JSONAPI-Resources / JSONAPI-Resources/jsonapi-resources
[v11] Sparse fieldsets allow for invalid types
Nobody has claimed this yet.
- Dominant language
- Ruby
- Stars
- 2.3k
- Forks
- 546
- PR merge metrics
- No merged PRs in 30d
Description
This issue is a (choose one):
- Problem/bug report.
- Feature request.
- Request for support. Note: Please try to avoid submitting issues for support requests. Use Gitter instead.
Checklist before submitting:
- I've searched for an existing issue.
- I've asked my question on Gitter and have not received a satisfactory answer.
- I've included a complete bug report template. This step helps us and allows us to see the bug without trying to reproduce the problem from your description. It helps you because you will frequently detect if it's a problem specific to your project.
- The feature I'm asking for is compliant with the JSON:API spec.
Description
When specifying sparse fieldsets, if you specify the type as the singular version of the type (i.e. fields[user]=name instead of fields[users]=name, the request succeeds instead of returning a 400.
Bug reports:
On the v0-11-dev branch with Ruby 3.3.5. The root of the issue is that classify is used to look up the resource class, which works the same for user and users, they both become UserResource, but then parse_fields doesn't verify that the type matches after getting the resource class back.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
On the v0-11-dev branch, locate parse_fields and trace how the sparse fieldset type is resolved to a resource class. Add coverage for fields[user]=name and verify that the singular type returns HTTP 400 while the valid plural form continues to succeed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rails, ruby
- Domain
- api, backend
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100