graphql-python / graphql-python/graphql-core

Validation/coercion of input variables violates the GraphQL spec

Aberta
#223 1 comentário 0 reações 0 responsáveis Ver no GitHub
Linguagem predominante
Python
Estrelas
531
Forks
146
Métricas de merge de PRs
Nenhum PR com merge em 30d

Descrição

When callling graphql-core's `execute()` function with `variable_values` which do not pass validation -- for example, including an unexpected key in the `variable_values` dictionary -- the current behavior is that an `ExecutionResult` object is returned from the function, with the associated GraphQLError present inside it. Instead, this should be treated as a Request error, according to the spec, meaning that a `GraphQLError` should be raised from `execute()`.

The GraphQL spec states:

> [Request errors](https://spec.graphql.org/October2021/#sec-Errors.Request-errors)
Request errors are raised before execution begins. This may occur due to a parse grammar or validation error in the requested document, an inability to determine which operation to execute, or **invalid input values for variables**.

This means that it is incorrect for the `coerce_variable_values` function to be returning a GraphQLError inside an ExecutionResult: https://github.com/graphql-python/graphql-core/blob/9dcf25e66f6ed36b77de788621cf50bab600d1d3/src/graphql/execution/values.py#L93-L99

doing so means that a response payload is returned containing both an "errors" key and a null "data" key. Again, this a violation of the spec:

> If a request error is raised, execution does not begin and the **data entry in the response must not be present**. The errors entry must include the error.

Guia de contribuição

Nenhum guia de contribuição indexado para este repositório

Direção de pesquisa

The issue points to coerce_variable_values in src/graphql/execution/values.py and graphql-core's execute() entry point. Read that function and its callers first; done means invalid variable_values cause GraphQLError to be raised as a request error, with no data entry in the response.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
graphql, python
Domínio
api, backend-api-design
Tipo de issue
Bug
Dificuldade
3/5
Tempo estimado
1-2 dias
Status de atividade
Estagnada
Clareza
Claramente especificada
Facilidade para iniciantes
35/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.