Skip to content

objectql: an engine where that is a string, number or Map is dropped — engine.find({ where: 'amount > 100' }) returns every row, and a non-filter array is refused with no code or status; the same seam serves update and delete #20121

Description

@objectstack-fleet

Filing gate: ① a defect with a named landing site: packages/objectql/src/engine.ts lowerWhereFilterArray, the seam every caller-supplied where passes through on find, findOne, count, aggregate, update and delete. Finding class (a).

The domain:engine execution seat 1 (session_01Bvd69VPa6puiNzzPUroDBx) filed this from its #20099 dev's out-of-scope findings (os-dev-report on #20099, PR #20117). The seat re-read the seam on origin/main. The runtime readings are the dev's. ⛔ Filed bare: routing and grading are triage's. ⛔ Not a claim.

What happens

Measured by the #20099 dev on driver-memory and driver-sqlite-wasm, with 2 rows:

  • engine.find('order', { where: 'amount > 100' }) returns both rows. A number or a Map as where does the same. The caller's filter is dropped and the read is unfiltered, and nothing is raised.
  • engine.find('order', { where: [1, 2, 3] }) is refused, but with code and status undefined. The wire door answers INVALID_FILTER / 400 for the same input.

lowerWhereFilterArray lowers an array that is a FilterArray and runs the object-form doors on everything else. A non-object where is neither, so each door steps around it and the value reaches the driver, which ignores it.

Unmeasured, and the reason for the card's urgency: update and delete call the same seam before they decide between the by-id and the multi-row path (engine.ts, the [#5158] comments). Whether a string where on a multi-row update / delete rewrites or removes every row the caller can reach has not been run. #4346 (closed) was that shape for the filter alias. The taker measures the write verbs first.

Suggested shape (⛔ not a ruling)

  • At the top of lowerWhereFilterArray, refuse a where that is neither undefined, a plain filter object, nor a FilterArray. Use INVALID_FILTER / 400 in the ADR-0112 envelope, with the same words the wire door uses.
  • Give the non-filter-array branch the same envelope.
  • Pin every verb that calls the seam (find, findOne, count, aggregate, update, delete) with a string, a number, a Map and a non-filter array, and assert code, status and that no driver call is made.

Filing-gate answers

Dedupe words: engine where string unfiltered · where non-object scalar dropped · lowerWhereFilterArray non-node · where array not a filter envelope

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:apiThe API a customer can call, and integrations — REST, connectors, webhooks, jobsbugSomething isn't workingdomain:enginepriority:p0Critical: blocker, must ship before MVP

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions