|
34 | 34 | * the rows above. The third is a `{ $field }` comparison whose column holds a |
35 | 35 | * list: the shape is legal, so it is judged on the record — refused when either |
36 | 36 | * compared column holds a list (or an object) on the record being judged. |
| 37 | + * |
| 38 | + * [#19886 stage 2e] The mirror of the first 2d row, with the list on the |
| 39 | + * RECORD's side and a literal bound — also judged on the record: |
| 40 | + * |
| 41 | + * | shape | before | after | |
| 42 | + * |---|---|---| |
| 43 | + * | `{ tags: { $gt: 'a' } }`, `tags` holding `['m']` | `'m' > 'a'` → `true`, the write **ALLOWED** | throws → 400 | |
| 44 | + * | `{ meta: { $lt: 'a' } }`, `meta` holding `{ a: 1 }` | `'[object Object]' < 'a'` → `true`, **ALLOWED** | throws → 400 | |
| 45 | + * | `{ tags: { $between: ['a', 'z'] } }`, `['m']` | `true` | throws → 400 | |
37 | 46 | */ |
38 | 47 |
|
39 | 48 | import { describe, it, expect } from 'vitest'; |
@@ -235,3 +244,124 @@ describe('[#19886 stage 2d] a { $field } comparison whose column holds a list is |
235 | 244 | } |
236 | 245 | }); |
237 | 246 | }); |
| 247 | + |
| 248 | +describe('[#19886 stage 2e] an ordering comparison whose STORED operand holds a list or an object is refused on that record', () => { |
| 249 | + const m = matchesFilterCondition; |
| 250 | + |
| 251 | + /** What a `json` column or a `multiple` lookup holds on a post-image. */ |
| 252 | + const STORED: Array<[string, unknown]> = [ |
| 253 | + ['a one-element list', ['m']], |
| 254 | + ['a multi-element list', ['a', 'z']], |
| 255 | + ['an empty list', []], |
| 256 | + ['a list of lists', [['m']]], |
| 257 | + ['a plain object', { a: 1 }], |
| 258 | + ['an empty object', {}], |
| 259 | + ]; |
| 260 | + |
| 261 | + /** Every ordering operator, each with a bound the coerced string form used to satisfy or not. */ |
| 262 | + const ORDERINGS: Array<[string, Record<string, unknown>]> = [ |
| 263 | + ['$gt', { $gt: 'a' }], |
| 264 | + ['$gte', { $gte: 'a' }], |
| 265 | + ['$lt', { $lt: 'z' }], |
| 266 | + ['$lte', { $lte: 'z' }], |
| 267 | + ['$between', { $between: ['a', 'z'] }], |
| 268 | + ]; |
| 269 | + |
| 270 | + for (const [storedName, stored] of STORED) { |
| 271 | + for (const [opName, spec] of ORDERINGS) { |
| 272 | + it(`${opName} on a field holding ${storedName}: INVALID_FILTER / 400`, () => { |
| 273 | + const err = refusalOf({ tags: spec }, { tags: stored }); |
| 274 | + expect(err.code).toBe('INVALID_FILTER'); |
| 275 | + expect(err.status).toBe(400); |
| 276 | + }); |
| 277 | + } |
| 278 | + } |
| 279 | + |
| 280 | + it('the refusal reaches every depth the evaluation reaches, and a negation cannot turn it into an answer', () => { |
| 281 | + const record = { owner: 'u1', tags: ['m'] }; |
| 282 | + const leaf = { tags: { $gt: 'a' } }; |
| 283 | + for (const filter of [ |
| 284 | + { $and: [{ owner: 'u1' }, leaf] }, |
| 285 | + { $or: [{ owner: 'nobody' }, leaf] }, |
| 286 | + { $not: leaf }, |
| 287 | + { $and: [{ $or: [{ $not: leaf }] }] }, |
| 288 | + ]) { |
| 289 | + const err = refusalOf(filter, record); |
| 290 | + expect(err.code).toBe('INVALID_FILTER'); |
| 291 | + expect(err.status).toBe(400); |
| 292 | + } |
| 293 | + }); |
| 294 | + |
| 295 | + it('a verdict already decided without the field does not reach it — judged per record, like the stage 2d refusal', () => { |
| 296 | + // Unlike the shape refusals, which judge the authored filter before any |
| 297 | + // record, this one judges a VALUE, so it fires where evaluation reads it. |
| 298 | + // Where it is not read, the answer does not depend on it either way. |
| 299 | + const record = { owner: 'u1', tags: ['m'] }; |
| 300 | + expect(m(record, { $or: [{ owner: 'u1' }, { tags: { $gt: 'a' } }] })).toBe(true); |
| 301 | + expect(m(record, { owner: 'nobody', tags: { $gt: 'a' } })).toBe(false); |
| 302 | + }); |
| 303 | + |
| 304 | + it('whatever the comparand: a number, a Date, null or a { $field } reference', () => { |
| 305 | + const record = { tags: ['m'], status: 'a' }; |
| 306 | + for (const spec of [ |
| 307 | + { $gt: 5 }, |
| 308 | + { $lt: new Date('2026-01-01T00:00:00.000Z') }, |
| 309 | + { $gte: null }, |
| 310 | + { $lte: { $field: 'status' } }, |
| 311 | + ]) { |
| 312 | + const err = refusalOf({ tags: spec }, record); |
| 313 | + expect(err.code).toBe('INVALID_FILTER'); |
| 314 | + expect(err.status).toBe(400); |
| 315 | + } |
| 316 | + }); |
| 317 | + |
| 318 | + it('a list written into a scalar field is judged the same way (a text or number field under an ordering check)', () => { |
| 319 | + for (const [record, filter] of [ |
| 320 | + [{ status: ['m'] }, { status: { $gt: 'a' } }], |
| 321 | + [{ amount: [500] }, { amount: { $gt: 10 } }], |
| 322 | + ] as const) { |
| 323 | + const err = refusalOf(filter, record); |
| 324 | + expect(err.code).toBe('INVALID_FILTER'); |
| 325 | + expect(err.status).toBe(400); |
| 326 | + } |
| 327 | + }); |
| 328 | + |
| 329 | + it('the SAME filter over a record holding one scalar is compared, not refused — the refusal is per record', () => { |
| 330 | + expect(m({ tags: 'm' }, { tags: { $gt: 'a' } })).toBe(true); |
| 331 | + expect(m({ tags: 'a' }, { tags: { $gt: 'a' } })).toBe(false); |
| 332 | + expect(m({ tags: 'm' }, { tags: { $between: ['a', 'z'] } })).toBe(true); |
| 333 | + expect(m({ tags: 5 }, { tags: { $lte: 10 } })).toBe(true); |
| 334 | + }); |
| 335 | + |
| 336 | + it('null, a missing field and a Date are untouched: no value is false, and a Date is a value', () => { |
| 337 | + for (const record of [{ tags: null }, {}]) { |
| 338 | + expect(m(record, { tags: { $gt: 'a' } })).toBe(false); |
| 339 | + expect(m(record, { tags: { $lt: 'z' } })).toBe(false); |
| 340 | + expect(m(record, { tags: { $between: ['a', 'z'] } })).toBe(false); |
| 341 | + } |
| 342 | + const at = new Date('2026-06-01T00:00:00.000Z'); |
| 343 | + expect(m({ at }, { at: { $gt: '2026-01-01T00:00:00.000Z' } })).toBe(true); |
| 344 | + expect(m({ at }, { at: { $lt: '2026-01-01T00:00:00.000Z' } })).toBe(false); |
| 345 | + expect(m({ at }, { at: { $between: ['2026-01-01T00:00:00.000Z', '2026-12-31T00:00:00.000Z'] } })).toBe(true); |
| 346 | + }); |
| 347 | + |
| 348 | + it('equality against a stored list keeps the answer stage 2a pinned — only ordering moved', () => { |
| 349 | + const record = { tags: ['m'] }; |
| 350 | + expect(m(record, { tags: 'm' })).toBe(false); |
| 351 | + expect(m(record, { tags: { $eq: 'm' } })).toBe(false); |
| 352 | + expect(m(record, { tags: { $ne: 'm' } })).toBe(true); |
| 353 | + expect(m(record, { tags: { $in: ['m'] } })).toBe(false); |
| 354 | + expect(m(record, { tags: { $nin: ['m'] } })).toBe(true); |
| 355 | + expect(m(record, { tags: { $exists: true } })).toBe(true); |
| 356 | + expect(m(record, { tags: { $null: false } })).toBe(true); |
| 357 | + }); |
| 358 | + |
| 359 | + it('the message withholds the field and the stored value', () => { |
| 360 | + const err = refusalOf({ secret_scope_column: { $gt: 'a' } }, { |
| 361 | + secret_scope_column: ['usr_member_one', 'usr_member_two'], |
| 362 | + }); |
| 363 | + for (const secret of ['secret_scope_column', 'usr_member_one', 'usr_member_two']) { |
| 364 | + expect(err.message).not.toContain(secret); |
| 365 | + } |
| 366 | + }); |
| 367 | +}); |
0 commit comments