-
Notifications
You must be signed in to change notification settings - Fork 1
feat(datasource-customizer): let replace_search take a field selection so a narrowed search is permission-checked #382
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
13 commits
Select commit
Hold shift + click to select a range
84fb9e3
feat(datasource-customizer): let replace_search take a field selectio…
PMerlet ac5b2c9
fix(agent): refuse an extended search the stack cannot describe
PMerlet b16d759
fix(datasource-customizer): match nothing when a search has no search…
PMerlet 5aa6bcc
fix(datasource-customizer): refuse a bare relation in a field selecti…
PMerlet 04b7ae3
test(datasource-customizer): pin the polymorphic behaviour of a searc…
PMerlet 540ea0b
fix(agent): narrow the extended-search refusal to a block
matthv ca75407
fix(agent): coerce a search term rather than strip a number
matthv 7f7bf0b
fix(agent): refuse a boolean search term, reorder the guards
matthv b692b1f
fix(search): exclude a relation named bare
matthv c4f3e79
fix(search): survive a nil logger, refuse an inert exclusion
matthv 84e1f54
fix(agent): read an explicit null subset search as absent
matthv d3378a3
test: pin what the search guard is actually wired to
matthv fc2ffa4
fix(search): guard the request-path logger, report an inert exclusion
matthv File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🟠 High
services/permissions.rb:334A numeric
searchvalue such as1234raisesNoMethodErrorincollect_search_usagesinstead of reaching the searchable collection or producing the route's request error.QueryStringParser.parse_searchdeliberately preserves non-string values, so only apply the blank-search check to strings.🚀 Reply "fix it for me" or copy this AI Prompt for your agent:
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Real bug, fixed at the source instead.
.stripis applied in three places —permissions.rb:334,search_collection_decorator.rb:36and:103— so guarding only the first would move theNoMethodErrorone layer down rather than remove it.parse_searchnow coerces the term and rejects a value that cannot be one (array, hash, boolean) with aBadRequestError, which closes all three.On the premise: the spec pinning
parse_searchreturning1234is titled "converts the query search parameter as string", so preserving the Integer was a bug its own name contradicted rather than a deliberate contract. The assertion now matches the title.Fixed in ca75407.