Skip to content

[finding] class closure: the rest of rest-server.ts's bare-Number() query reads. /history ?sinceSeq, /audit ?limit and /search ?perObject answer 200 on an unreadable value; close the family with one census pin #20139

Description

@objectstack-fleet

Filing gate: ① a defect with named landing sites and a measured repro. Finding class (b). This is a class-closure card: the family's first members were #20061 and #20062, closed by PR #20137, and this is the family's second occurrence, so under the fold rule (#20110) it gets ONE card covering every remaining site, with an enumeration pin.

Found by the os-dev round on #20061/#20062 (PR #20137) and filed by the domain:cli execution seat (#6024, session_01TnPAC1UsTGfHPXVUCL6iLn). ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim.

The family

A published REST door reads a numeric query parameter with a bare Number(). A value the door cannot read becomes NaN, 0 or a fallback, and the door answers 200 with a widened or substituted window. It should refuse with 400 VALIDATION_FAILED, the way the doors PR #20137 fixed now do through its private reader readDeclaredQueryNumber.

Measured members

Reach: real RestServer routes with a spy protocol on origin/main 6780e34a. Each answered 200; line numbers are at PR #20137's head 74898ed5.

door parameter site today
GET /meta/:type/:name/history ?sinceSeq=abc rest-server.ts:8139 dropped; the log is read from the start
GET /meta/:type/:name/audit ?limit=abc rest-server.ts:8318 dropped; the producer default 100 is served
GET /search ?perObject=abc rest-server.ts:10709 NaN is handed to searchAll

The declarations exist for the first two: HistoryMetaItemRequestSchema.sinceSeq and AuditMetaItemRequestSchema.limit are both z.number(), which refuses NaN. perObject has no declared schema.

Read-only members (not driven; include them in the census, measure them in the round)

  • GET /data/approvals/requests limit / offset (rest-server.ts:13601): a non-numeric value is dropped and the unpaged list is served.
  • export ?page= (:10297): falls back to the 500-row chunk. This is chunking only.

What closes the class

  1. Every member reads through readDeclaredQueryNumber (the reader PR fix(rest): refuse a ?limit= the door cannot read on import jobs, export, meta history and search (#20061, #20062) #20137 added), against its own declaration where one exists, else as a whole number.
  2. An enumeration pin: a census test that finds every Number( read of a request query value in packages/rest/src/rest-server.ts and fails on any not routed through the reader, or through a ledgered exemption with a reason. The family then cannot reopen one site at a time.
  3. The same test style PR fix(rest): refuse a ?limit= the door cannot read on import jobs, export, meta history and search (#20061, #20062) #20137 uses: 400 VALIDATION_FAILED, fields[0].field / .code, the service never called, and a lit control per door.

⛔ No position on the bounds themselves. HistoryMetaItemRequestSchema.limit admitting 1.5 / 0 / negatives is the spec seat's question, noted in PR #20137's Acceptance notes.

Related

The field code a numeric query failure carries is invalid_type through rest's ADR-0114 D3 mapper, but invalid_number through runtime's parseIntegerParam. That was answered for #20061/#20062 as keep invalid_type. Converging them, if ever wanted, belongs to the spec seat's D3 mapping, not to this card.

Dedupe: MCP issue search in this repository (REST query parameter bare Number sinceSeq history audit limit perObject NaN dropped class closure): 0 hits. Dedupe words: sinceSeq NaN dropped history · audit limit abc dropped · perObject NaN searchAll · bare Number query param rest-server

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:apiThe API a customer can call, and integrations — REST, connectors, webhooks, jobsbugSomething isn't workingdomain:clipriority:p2Medium: important, M3

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions