JSONAPI-Resources / JSONAPI-Resources/jsonapi-resources

[v11] Sparse fieldsets allow for invalid types

Offen
#1,460 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

Vorherrschende Sprache
Ruby
Sterne
2.3k
Forks
546
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

This issue is a (choose one):

  • Problem/bug report.
  • Feature request.
  • Request for support. Note: Please try to avoid submitting issues for support requests. Use Gitter instead.

Checklist before submitting:

  • I've searched for an existing issue.
  • I've asked my question on Gitter and have not received a satisfactory answer.
  • I've included a complete bug report template. This step helps us and allows us to see the bug without trying to reproduce the problem from your description. It helps you because you will frequently detect if it's a problem specific to your project.
  • The feature I'm asking for is compliant with the JSON:API spec.

Description

When specifying sparse fieldsets, if you specify the type as the singular version of the type (i.e. fields[user]=name instead of fields[users]=name, the request succeeds instead of returning a 400.

Bug reports:

On the v0-11-dev branch with Ruby 3.3.5. The root of the issue is that classify is used to look up the resource class, which works the same for user and users, they both become UserResource, but then parse_fields doesn't verify that the type matches after getting the resource class back.

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Rechercherichtung

Suche im Branch v0-11-dev nach parse_fields und verfolge, wie der Sparse-Fieldset-Typ zu einer Ressourcenklasse aufgelöst wird. Füge Tests für fields[user]=name hinzu und verifiziere, dass der Singulartyp HTTP 400 zurückgibt, während die gültige Pluralform weiterhin erfolgreich ist.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
rails, ruby
Bereich
api, backend
Issue-Typ
Bug
Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
45/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.