Filing gate: ① a defect with a named landing site: the comparand-type door (#7872, normalizeFilterComparandTypes) lets a non-numeric string through against a number field, and PostgreSQL then refuses the bind (invalid input syntax) as a 500. The landing site is the type door in packages/spec/src/data / packages/objectql, or SqlDriver's bind, depending on the chosen answer.
Finding class (a). reach: was measured at the public REST door (below).
The domain:engine execution seat 1 (session_01Bvd69VPa6puiNzzPUroDBx) filed this from its #20263 dev's report (os-dev-report 5859428680, out_of_scope_findings[5]), re-measured by the at-tier review of PR #20307 (record 5860498332). ⛔ Filed bare: routing and grading are triage's. ⛔ Not a claim.
What happens
Measured at 2dccb7d494, which equals main on this path.
| door |
InMemoryDriver |
SQLite |
PostgreSQL |
REST …/query, where { amount: { $gt: "abc" } } |
200, no rows |
200, no rows |
500 DATABASE_ERROR ("Internal server error") |
engine.find, the same |
200, no rows |
200, no rows |
DATABASE_ERROR |
the same as a per-aggregation filter |
200, count 0 |
200, count 0 |
200, count 0 (evaluated in memory) |
Suggested shape (⛔ not a ruling)
One answer for every dialect and position, decided once. Either:
Pin it on the three drivers, at where and the per-aggregation filter, through the engine and REST.
Filing-gate answers
Dedupe words: postgres 500 non-numeric string number field where · number comparand string abc database_error · comparand type door string on number field
Filing gate: ① a defect with a named landing site: the comparand-type door (#7872,
normalizeFilterComparandTypes) lets a non-numeric string through against anumberfield, and PostgreSQL then refuses the bind (invalid input syntax) as a 500. The landing site is the type door inpackages/spec/src/data/packages/objectql, or SqlDriver's bind, depending on the chosen answer.Finding class (a).
reach:was measured at the public REST door (below).The
domain:engineexecution seat 1 (session_01Bvd69VPa6puiNzzPUroDBx) filed this from its #20263 dev's report (os-dev-report5859428680,out_of_scope_findings[5]), re-measured by the at-tier review of PR #20307 (record 5860498332). ⛔ Filed bare: routing and grading are triage's. ⛔ Not a claim.What happens
Measured at
2dccb7d494, which equalsmainon this path.…/query,where { amount: { $gt: "abc" } }DATABASE_ERROR("Internal server error")engine.find, the sameDATABASE_ERRORfilter[500]on WRITE. This card is the READ comparand.Suggested shape (⛔ not a ruling)
One answer for every dialect and position, decided once. Either:
numberfield at the comparand-type door (INVALID_FILTER/ 400, the An unparseable date comparand on a datetime filter is passed through and compares false — HTTP 200, zero rows, no diagnostic — while an unknown{placeholder}is correctly rejected 400 (17.0.0 GA) #8690 posture for temporal fields);Pin it on the three drivers, at
whereand the per-aggregationfilter, through the engine and REST.Filing-gate answers
domain:engine).closedincluded:postgres 500 non-numeric string comparand number field where invalid input syntax integer→ record validator's number arm accepts any value whose Number() is finite, so POST /api/v1/data with a number field [500] answers 201 and driver-sql stores the text '[500]' #20309 (the write door, open; related, not this), analytics 的string[]值往返对字符串比较数也有损:{code: {$eq: '007'}}绑成数字7、'null'绑成真 NULL、'true'绑成1—— 文本列静默取到错行 #5526 and analytics: a measure naming a missing field 500s with SQLITE_ERROR instead of a 400 naming the field #4437 (analytics, closed), none this.Dedupe words:
postgres 500 non-numeric string number field where·number comparand string abc database_error·comparand type door string on number field