graphql-python / graphql-python/gql

DSL does not provide expected argument validation

Đang mở
#355 1 bình luận 0 reaction 0 người được giao Xem trên GitHub
type: feature
Ngôn ngữ chính
Python
Star
1.7k
Fork
195
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

**Describe the bug**

- When creating a query with `gql.gql()`, the query string is checked for invalid arguments, and raises an exception if any are found. (**expected behavior**)
- When creating a query with `gql.dsl.dsl_gql()`, the arguments are not checked, causing unexpected return values. (**unexpected behavior**)

I've been able to recreate this using the [countries api](https://countries.trevorblades.com/) used in the [docs](https://gql.readthedocs.io/en/latest/advanced/dsl_module.html#sync-example).

**To Reproduce**

Jump to step 5 to see the actual improper behavior.

1. Set up the transport/client.

```py
import json

import gql
from gql.transport.requests import RequestsHTTPTransport as Transport
from gql import dsl

url = "https://countries.trevorblades.com/"

transport = Transport(url=url)
client = gql.Client(transport=transport, fetch_schema_from_transport=True)

# Fetch the schema (lemme know if there's a recommended approach for this).
client.connect_sync()
client.close_sync()
ds = dsl.DSLSchema(client.schema)
```

2. Run a good query using strings.

```py
good_query_str = gql.gql(
"""
query {
continents (filter:{code:{eq:"AN"}}) {
code
name
}
}
"""
)
result = client.execute(good_query_str)
print(json.dumps(result, indent=2))
```

Result:

```json
{
"continents": [
{
"code": "AN",
"name": "Antarctica"
}
]
}
```

3. Run a bad query using strings. The only change here is using `'AN' ` directly as an argument to `code`, instead of providing the `eq` directive.

```py
bad_query_str = gql.gql(
"""
query {
continents (filter:{code:"AN"}) {
code
name
}
}
"""
)
result = client.execute(bad_query_str)
print(json.dumps(result, indent=2))
```

Result:

```py
GraphQLError: Expected value of type 'StringQueryOperatorInput', found "AN".

GraphQL request:3:34
2 | query {
3 | continents (filter:{code:"AN"}) {
| ^
4 | code
```

4. Run a good query using DSL.

```py
good_query_dsl = dsl.dsl_gql(
dsl.DSLQuery(
ds.Query.continents(
filter={
'code': {'eq': 'AN'}
}
).select(
ds.Continent.code,
ds.Continent.name,
)
)
)
result = client.execute(good_query_dsl)
print(json.dumps(result, indent=2))
```

Result:

```json
{
"continents": [
{
"code": "AN",
"name": "Antarctica"
}
]
}
```

5. Run a bad query using DSL. Same deal, just remove the 'eq' level of filter specification. Note that the result is an unfiltered response.

```py
bad_query_dsl = dsl.dsl_gql(
dsl.DSLQuery(
ds.Query.continents(
filter={
'code': 'AN'
}
).select(
ds.Continent.code,
ds.Continent.name,
)
)
)
result = client.execute(bad_query_dsl)
print(json.dumps(result, indent=2))
```

Result:

```json
{
"continents": [
{
"code": "AF",
"name": "Africa"
},
{
"code": "AN",
"name": "Antarctica"
},
{
"code": "AS",
"name": "Asia"
},
{
"code": "EU",
"name": "Europe"
},
{
"code": "NA",
"name": "North America"
},
{
"code": "OC",
"name": "Oceania"
},
{
"code": "SA",
"name": "South America"
}
]
}
```

**Expected behavior**

Step 5 should raise an equivalent exception to step 3.

**System info (please complete the following information):**

- OS: Wins 10
- Python version: 3.9.12
- gql version: 3.4.0
- graphql-core version: 3.2.1

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.