graphql-python / graphql-python/graphql-core
Validation/coercion of input variables violates the GraphQL spec
- Linguagem predominante
- Python
- Estrelas
- 531
- Forks
- 146
- Métricas de merge de PRs
- Nenhum PR com merge em 30d
Descrição
When callling graphql-core's `execute()` function with `variable_values` which do not pass validation -- for example, including an unexpected key in the `variable_values` dictionary -- the current behavior is that an `ExecutionResult` object is returned from the function, with the associated GraphQLError present inside it. Instead, this should be treated as a Request error, according to the spec, meaning that a `GraphQLError` should be raised from `execute()`.
The GraphQL spec states:
> [Request errors](https://spec.graphql.org/October2021/#sec-Errors.Request-errors)
Request errors are raised before execution begins. This may occur due to a parse grammar or validation error in the requested document, an inability to determine which operation to execute, or **invalid input values for variables**.
This means that it is incorrect for the `coerce_variable_values` function to be returning a GraphQLError inside an ExecutionResult: https://github.com/graphql-python/graphql-core/blob/9dcf25e66f6ed36b77de788621cf50bab600d1d3/src/graphql/execution/values.py#L93-L99
doing so means that a response payload is returned containing both an "errors" key and a null "data" key. Again, this a violation of the spec:
> If a request error is raised, execution does not begin and the **data entry in the response must not be present**. The errors entry must include the error.
Guia de contribuição
Nenhum guia de contribuição indexado para este repositório
Direção de pesquisa
The issue points to coerce_variable_values in src/graphql/execution/values.py and graphql-core's execute() entry point. Read that function and its callers first; done means invalid variable_values cause GraphQLError to be raised as a request error, with no data entry in the response.
Escrita pelo modelo de indexação a partir do texto da issue.
Avaliação
- Stack de tecnologia
- graphql, python
- Domínio
- api, backend-api-design
- Tipo de issue
- Bug
- Dificuldade
- 3/5
- Tempo estimado
- 1-2 dias
- Status de atividade
- Estagnada
- Clareza
- Claramente especificada
- Facilidade para iniciantes
- 35/100