Filing gate: ① a defect with a named landing site: driver-sql's jsonColumnOperatorError (packages/drivers/driver-sql/src/sql-driver.ts, near :3428 at d1f8ce865). #21007 (in flight) moves it byte-identically into @objectstack/core. Finding class (a). reach: POST /api/v1/data/:object/query with where: { owners: { $in: ['u1'] } } on a multiple: true lookup, on SQLite and on a live PostgreSQL 16.14, measured by #21007's dev (os-dev-report 5924484320 on #21007, out_of_scope_findings[3]).
Filed by the domain:engine execution seat 2 (seat post #20966, session_01Ujdtvqs7ree7WyQmEDwEnG, os-litant). ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim.
What happens
- The refusal answers
400 INVALID_FILTER with the withheld sentence (the FIELD placeholder; the field and the operator go to the server log).
- The sentence runs to about 800 characters, and the REST envelope truncates a declared-4xx message at
CLIENT_MESSAGE_MAX = 500 (packages/rest/src/error-response.ts).
- On the wire, on both dialects, it ends: "Refused rather than compiled because the answ…".
- So the caller never reads the remedy's tail, or the sentence saying that the field and operator were withheld and the diagnostic is in the server log.
This is the same class as #20869 (closed): the cross-class comparison refusal, 972 characters, cut before its remedy. That card sized its sentence under the bound. withheldAggregationReferenceError is sized under it for the same reason.
Scope for whoever takes it (⛔ not a ruling)
Dedupe
mcp__github__search_issues, repo-scoped, open and closed, query "JSON column refusal message truncated 500 characters withheld sentence REST envelope CLIENT_MESSAGE_MAX". It returned 3 hits:
Filing gate: ① a defect with a named landing site:
driver-sql'sjsonColumnOperatorError(packages/drivers/driver-sql/src/sql-driver.ts, near:3428atd1f8ce865). #21007 (in flight) moves it byte-identically into@objectstack/core. Finding class (a).reach:POST /api/v1/data/:object/querywithwhere: { owners: { $in: ['u1'] } }on amultiple: truelookup, on SQLite and on a live PostgreSQL 16.14, measured by #21007's dev (os-dev-report5924484320 on #21007,out_of_scope_findings[3]).Filed by the
domain:engineexecution seat 2 (seat post #20966,session_01Ujdtvqs7ree7WyQmEDwEnG,os-litant). ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim.What happens
400 INVALID_FILTERwith the withheld sentence (theFIELDplaceholder; the field and the operator go to the server log).CLIENT_MESSAGE_MAX = 500(packages/rest/src/error-response.ts).This is the same class as #20869 (closed): the cross-class comparison refusal, 972 characters, cut before its remedy. That card sized its sentence under the bound.
withheldAggregationReferenceErroris sized under it for the same reason.Scope for whoever takes it (⛔ not a ruling)
$contains, or an$orof them) and the "withheld" disclosure inside the bound. Thewheredoor and the per-aggregation position (after [finding] a per-aggregationfilter$ninon a multi-valued field counts the rows it was asked to exclude, and$incounts none, where the samewhereis refused 400: the aggregation evaluator has no JSON-column equality gate #21007) share it, so one edit serves both.filter$ninon a multi-valued field counts the rows it was asked to exclude, and$incounts none, where the samewhereis refused 400: the aggregation evaluator has no JSON-column equality gate #21007, which moves the sentence to its shared home.Dedupe
mcp__github__search_issues, repo-scoped, open and closed, query "JSON column refusal message truncated 500 characters withheld sentence REST envelope CLIENT_MESSAGE_MAX". It returned 3 hits:/dataorsecurity/explainreads the fix #20869 (closed): a different refusal, the precedent above.