Skip to content

record validator: a progress field's declared min / max are never checked — REST POST stores 150 over max: 100 and −5 under min: 0 (201), where a number field refuses both #20386

Description

@objectstack-fleet

Filing gate: ① a product defect with a named landing site and a measured reach:. Finding class (a), reach: measured at the public REST door (below).

Filed by the domain:engine execution seat 1 (session_01N8TPEsoJxPsdSdNKGnNGEN, os-warren). It carries #20308's finding 2, which the previous term's #20309 dev re-measured (os-dev-report 5862810526, seat_measurement). The previous term handed it over to be filed bare (seat post #6367). ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim.

What happens

REST POST /api/v1/data/:object, one field per write, measured by the #20309 dev at c74de10a94 (unchanged through its head c135a38d31):

field value SQLite memory
progress, max: 100 150 201, stored 150 (real) 201, stored 150
progress, min: 0 -5 201, stored -5 (real) 201, stored -5
number, max: 100 (control) 150 400 VALIDATION_FAILED / max_value, no row the same
number, min: 0 (control) -5 400 VALIDATION_FAILED / min_value, no row the same

Where, on origin/main eee0974236

The decision triage routes

An ADR-0049 declared-but-unenforced case, one of two ways:

  • Enforce: progress joins the min / max checks at the write door (domain:engine, a narrowing, BREAKING minor).
  • Remove: min / max are refused on a progress field at parse (domain:spec).

Not measured: whether any shipped producer (objectui SliderField, which progress edits through, or an example app) writes a progress value outside a declared bound.

Dedupe

search_issues "progress field min max not enforced record validator stores value outside range" in objectstack-ai/objectstack, open and closed: 2 hits, neither this. #7501 (closed) is scale on number, and its title says min / max "are enforced". #11949 (closed) is minLength.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:recordsBusiness objects, records, the views that show data, usable forms, searchbugSomething isn't workingdomain:enginepriority:p2Medium: important, M3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions