loopbackio / loopbackio/loopback-next
Patch with no query updates all records in the database
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 5.1k
- Forks
- 1.1k
- Avg merge
- 2d 21h
- Merged PRs (30d)
- 27
Description
While struggling to to learn how to write the correct query
to patch only one record, I tried no query and the default of
patch all records was performed.
Steps to reproduce
- Following the the todo-list tutorial
lb4 example todo-list
cd loopback4-example-todo-list
npm start
-
Browse to the API explorer at http://127.0.0.1:3000
-
Notice that the database is prepopulated
a. With GET todo-lists/count
- Click
Try It out - remove the default query
- press the
executebutton - see result
{ "count": 2 }
b. With button GET todo-lists/
- Click
Try It out - remove the default query
- press the execute button
- see the response has two lists
[ { "id": 1, "title": "Sith lord's check list", "color": "blue" }, { "id": 2, "title": "My daily chores", "color": "red" } ]
c. Click button
GET /todo-lists/{id}/todos- Click
Try It out - Enter
1for the id number of the first list - remove the default query
- press the execute button
- see the response is quantity three pre-populated todos
id's 1, 2 and 4 .
WARNING: about to (accidentally) patch all the todos in the list!
d. Click button
PATCH /todo-lists/{id}/todos- Click
Try It out - Enter
1for the id number of the first list - remove the default query
- add some replacement data in the request body, for example:
{ "id": 4, "title": "my-title-string", "desc": "a short description string", "isComplete": false, "todoListId": 1 } - press the
executebutton - see the response is
{ "count": 3 }
e. Re-perform step c. above to see the result is:
[ { "id": 1, "title": "my-title-string", "desc": "a short description string", "isComplete": false, "todoListId": 1 }, { "id": 2, "title": "my-title-string", "desc": "a short description string", "isComplete": false, "todoListId": 1 }, { "id": 4, "title": "my-title-string", "desc": "a short description string", "isComplete": false, "todoListId": 1 } ]- an array where all the records have been unceremoniously patched to equal the replacement data! The list count is still { "count": 2 }.
- Click
Current Behavior
- Default (accidental) patch of all records.
Expected Behavior
- My expectation is that at least nothing would happen
accidentally. Even better, no patch-all would occur
and that a somewhat helpful error message would be
returned stating that an empty query is not allowed with
a patch request.
Link to reproduction sandbox
__N/A__
Additional information
- linux x64 14.15.1
@loopback/example-todo-list@3.7.1 /home/northdecoder/workspace/loopback4-example-todo-list
├── @loopback/boot@3.2.0
├── @loopback/core@2.14.0
├── @loopback/repository@3.4.0
├── @loopback/rest@9.1.2
├── @loopback/rest-explorer@3.0.6
├── @loopback/service-proxy@3.0.6
├── loopback-connector-rest@4.0.1
Related Issues
Issue #
- Deletes all with no query issue# 7017. Not sure the code is related, however the pattern of behavior is similar.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the empty-query PATCH through the todo-list tutorial's API Explorer endpoint, then inspect the @loopback/repository and @loopback/rest packages involved in handling it. Compare the behavior with related issue #7017. Done means an empty query no longer patches every todo and the endpoint returns a helpful error or otherwise performs no update.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- nodejs, typescript
- Domain
- api, backend
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100