Filing gate: ① a product defect with a named landing site and a measured reach:. Finding class (a), a silent wrong value stored. reach: was measured at REST POST /api/v1/data/:object/import (JSON rows, writeMode: insert) with the real RestServer, on InMemoryDriver and on SqlDriver (better-sqlite3), by the #20309 dev at base 851af0c27 and at PR #20496's head.
Filed by the domain:engine execution seat 1 (session_01N8TPEsoJxPsdSdNKGnNGEN, os-warren) from the #20309 dev's report (os-dev-report 5876625514, out_of_scope_findings[0]). ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim.
What happens
A number field, imported through /import:
| cell |
stored |
import answer |
a plain write door (POST / PATCH / batch) |
'3,14' |
314 |
ok 1, errors 0 |
400 invalid_number |
'1,5' |
15 |
ok 1, errors 0 |
400 invalid_number |
'1.000,5' |
1.0005 |
ok 1, errors 0 |
400 invalid_number |
'1,2,3' |
123 |
ok 1, errors 0 |
400 invalid_number |
A decimal-comma spelling, common in a European CSV, is stored as a different number, and the import reports success.
Why
parseNumberCell in packages/rest/src/import-coerce.ts removes every comma (replace(/,/g, '')) before parsing, as if every comma grouped thousands. It never checks that a comma sits at a thousands boundary. So '1,5' becomes 15, and '1.000,5' becomes 1.0005.
The import reader is documented as deliberately more tolerant than the platform's numeric grammar (filter-number-comparand-declared-type.ts, PR #20414; the spec module header says so). The dev measured 8 of the grammar's 41 rows where the reader accepts what the grammar refuses. The other 7 (padding, +, .5, 007, '1,000') are admitted to the number the author meant, so only the comma misread changes the value.
Suggested shape (⛔ not a ruling)
- Accept a comma only as a well-formed thousands group (
1,000, 12,345.67). Refuse anything else in the cell with the row's error, never a silent other number.
- Or, if a locale-aware import is wanted, make the decimal separator an explicit import option. That is a design question for triage.
- Pin
/import on memory and SQLite with the four cells above.
Dedupe
search_issues in objectstack-ai/objectstack, open and closed, for "import decimal comma parseNumberCell thousands separator number field stored wrong value CSV import" and "import-coerce number cell comma stripped 1,5 stored 15": 0 hits.
Dedupe words: import decimal comma · parseNumberCell thousands separator · '1,5' stored 15 · import-coerce comma stripped · CSV import locale number
Filing gate: ① a product defect with a named landing site and a measured
reach:. Finding class (a), a silent wrong value stored.reach:was measured at RESTPOST /api/v1/data/:object/import(JSON rows,writeMode: insert) with the realRestServer, onInMemoryDriverand onSqlDriver(better-sqlite3), by the #20309 dev at base851af0c27and at PR #20496's head.Filed by the
domain:engineexecution seat 1 (session_01N8TPEsoJxPsdSdNKGnNGEN,os-warren) from the #20309 dev's report (os-dev-report5876625514,out_of_scope_findings[0]). ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim.What happens
A number field, imported through
/import:'3,14'314invalid_number'1,5'15invalid_number'1.000,5'1.0005invalid_number'1,2,3'123invalid_numberA decimal-comma spelling, common in a European CSV, is stored as a different number, and the import reports success.
Why
parseNumberCellinpackages/rest/src/import-coerce.tsremoves every comma (replace(/,/g, '')) before parsing, as if every comma grouped thousands. It never checks that a comma sits at a thousands boundary. So'1,5'becomes15, and'1.000,5'becomes1.0005.The import reader is documented as deliberately more tolerant than the platform's numeric grammar (
filter-number-comparand-declared-type.ts, PR #20414; the spec module header says so). The dev measured 8 of the grammar's 41 rows where the reader accepts what the grammar refuses. The other 7 (padding,+,.5,007,'1,000') are admitted to the number the author meant, so only the comma misread changes the value.Suggested shape (⛔ not a ruling)
1,000,12,345.67). Refuse anything else in the cell with the row's error, never a silent other number./importon memory and SQLite with the four cells above.Dedupe
search_issuesinobjectstack-ai/objectstack, open and closed, for "import decimal comma parseNumberCell thousands separator number field stored wrong value CSV import" and "import-coerce number cell comma stripped 1,5 stored 15": 0 hits.Dedupe words:
import decimal comma·parseNumberCell thousands separator·'1,5' stored 15·import-coerce comma stripped·CSV import locale number