JSONAPI-Resources / JSONAPI-Resources/jsonapi-resources

[v11] Sparse fieldsets allow for invalid types

Open
#1,460 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Ruby
Stars
2.3k
Forks
546
PR merge metrics
No merged PRs in 30d

Description

This issue is a (choose one):

  • Problem/bug report.
  • Feature request.
  • Request for support. Note: Please try to avoid submitting issues for support requests. Use Gitter instead.

Checklist before submitting:

  • I've searched for an existing issue.
  • I've asked my question on Gitter and have not received a satisfactory answer.
  • I've included a complete bug report template. This step helps us and allows us to see the bug without trying to reproduce the problem from your description. It helps you because you will frequently detect if it's a problem specific to your project.
  • The feature I'm asking for is compliant with the JSON:API spec.

Description

When specifying sparse fieldsets, if you specify the type as the singular version of the type (i.e. fields[user]=name instead of fields[users]=name, the request succeeds instead of returning a 400.

Bug reports:

On the v0-11-dev branch with Ruby 3.3.5. The root of the issue is that classify is used to look up the resource class, which works the same for user and users, they both become UserResource, but then parse_fields doesn't verify that the type matches after getting the resource class back.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

On the v0-11-dev branch, locate parse_fields and trace how the sparse fieldset type is resolved to a resource class. Add coverage for fields[user]=name and verify that the singular type returns HTTP 400 while the valid plural form continues to succeed.

Written by the indexing model from the issue text.

Assessment

Tech stack
rails, ruby
Domain
api, backend
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.