Repository navigation
feat: refuse unrecognized wire input instead of ignoring it - #353
Merged
Merged
Conversation
The ./wire request parsers now refuse a query param or body key their endpoint does not define, at any depth, and take only true/false for boolean params. An ignored name answers a different request than the one sent: a misspelled filter widens a query, a stale field mints the wrong token. Specified in wire-format.md § Unrecognized input, with four new error fixtures. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_018rAh3A4jeexocb6UcZRAwa
🦋 Changeset detectedLatest commit: 1a27505 The changes in this PR will be included in the next version bump. This PR includes changesets to release 11 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
A single-value query param repeated (?includeDeleted=true&includeDeleted=junk) was read as its first value with the rest silently dropped, which the Unrecognized input rule forbids. Only the filter lists (typeId, baseId, appId, createdBySubject, createdByPrincipal, tag, kind) may repeat now. WIRE_RECORD_KEYS is checked against keyof StackRecord, so a new record field fails to compile until the create body accepts it. Also document that parseQueryBody() takes an absent body as undefined, and name /auth/token among the endpoints a server parses itself. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_0193gggj973cZHEHdWJHXGTQ
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The
./wirerequest parsers now return a 400 (bad_request) for input their endpoint doesn't define. Before, they ignored it. An ignored name answers a different request than the one the client sent, and the client never finds out:purgedoes a soft delete insteadChanges by parser:
parseQueryParams(),parseChangeParams(),parseJournalParams():trueorfalse.parseChangeParams()acceptssince, the resume cursor the server reads itself.parseQueryBody():filter,createdBy,attachment,createdAt/updatedAt,relatedToand its target (checked per kind), andsort.includeDeleted/includeUnlistedmust be booleans, andcursormust be a string.createOptionsFromWireRecord(): a key that no wire record carries is refused. Server-assigned keys (createdBy,updatedBy,version, and so on) are still accepted and then ignored, as the spec already requires.changesFromWireBody()already refused unknown keys and is unchanged.Spec
New section:
docs/spec/wire-format.md§ Unrecognized input. It states the rule and three exceptions:Four new error fixtures:
error-bad-request-unknown-query-paramerror-bad-request-non-boolean-paramerror-bad-request-unknown-query-body-keyerror-bad-request-unknown-record-keyVerification
pnpm run format:check && pnpm run check:refs && pnpm run lint && pnpm -r test && pnpm run build && pnpm run typecheckall pass.I also ran haverstack/server's test suite against this build. Two tests failed, both for expected reasons:
entityIdkey. That test is already fixed on feat: adopt core 0.38's streamlined API server#130.?token=now gets a 400 where it expected an anonymous connection.Notes for reviewers
minor. This is a breaking change for any client that sends extra names, but there are no existing users to break (see AGENTS.md § No backward compatibility).adapter-api's conformance test lists the four new fixtures as server-only, becauseAPIAdapternever sends a name the wire doesn't define.?token=test needs updating.Stack, not wire parsing, and belongs in a separate change.🤖 Generated with Claude Code
https://claude.ai/code/session_018rAh3A4jeexocb6UcZRAwa
Generated by Claude Code