JSONAPI-Resources / JSONAPI-Resources/jsonapi-resources
[v11] Sparse fieldsets allow for invalid types
Nessuno ha ancora preso questa issue.
- Lingua principale
- Ruby
- Stelle
- 2.3k
- Fork
- 546
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Descrizione
This issue is a (choose one):
- Problem/bug report.
- Feature request.
- Request for support. Note: Please try to avoid submitting issues for support requests. Use Gitter instead.
Checklist before submitting:
- I've searched for an existing issue.
- I've asked my question on Gitter and have not received a satisfactory answer.
- I've included a complete bug report template. This step helps us and allows us to see the bug without trying to reproduce the problem from your description. It helps you because you will frequently detect if it's a problem specific to your project.
- The feature I'm asking for is compliant with the JSON:API spec.
Description
When specifying sparse fieldsets, if you specify the type as the singular version of the type (i.e. fields[user]=name instead of fields[users]=name, the request succeeds instead of returning a 400.
Bug reports:
On the v0-11-dev branch with Ruby 3.3.5. The root of the issue is that classify is used to look up the resource class, which works the same for user and users, they both become UserResource, but then parse_fields doesn't verify that the type matches after getting the resource class back.
Guida per i contributori
Nessuna guida per i contributori indicizzata per questo repository
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Direzione di ricerca
Nel branch v0-11-dev, individua parse_fields e segui come il tipo di sparse fieldset viene risolto in una classe di risorsa. Aggiungi la copertura per fields[user]=name e verifica che il tipo singolare restituisca HTTP 400, mentre la forma plurale valida continui ad avere successo.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- rails, ruby
- Ambito
- api, backend
- Tipo di issue
- Bug
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Stato di attività
- Ferma
- Chiarezza
- Abbastanza chiara
- Idoneità per principianti
- 45/100