Repository navigation
Fix current authorization of preloaded generated relationship targets - #98
Merged
Merged
Conversation
This was referenced Oct 1, 2026
Dastari
changed the base branch from
fix/cross-crate-generated-relations-20261001
to
main
October 1, 2026 07:18
1 of 2 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Generated nullable relationships returned preloaded objects before current target authorization or complete ownership-key resolution. A forged snapshot could therefore expose a denied or cross-tenant target. Resolve the authoritative target through the existing typed query/uncached batch loader, recheck current entity/row authority, and preflight selected target fields with their actual child contexts. Denial preserves an authorized parent, nulls its nullable child and attaches a sanitized relationship-path error. Missing/mismatched targets ordinarily return null without errors; SQL-complete visibility treats hidden rows as absent without an unauthorized existence probe.
Remove generated parents' pool-only eager preloads, which could query a denied target and fail the whole parent before nullable traversal. Keep explicit preload APIs source compatible. Apply current SQL visibility before relation paging/counting and include it in batch identity alongside DbAuthContext. Callback-only/prefiltered to-many policies require the existing host AuthorizedScanConfig: examine bounded database batches to exhaustion, retain only the requested visible window, and fail closed on an exhausted budget rather than returning partial counts or false end-of-data. Residual scans run per parent; SQL-complete loads remain batched. Existing SDL and cursor formats are unchanged. Policy callbacks may run during preflight and ordinary resolution; both receive the actual child context/arguments/alias/path. No cross-statement snapshot isolation under concurrent external DML is promised.
This is a separately reviewable dependent PR based on #96 at
4617b332014758387a3c271a7b30a5aff4873453for the two-crate regression fixture. #96's narrow cross-crate fix remains unchanged. It does not depend on PR A or B–D, add joined/computed queries/group continuation/private view adapters, or change private repository roots. ORM/macros are aligned at 0.33.5. Version order: #96 (0.33.4), this fix (0.33.5), #97 (0.34.0); realign/rebase the pending patches if the owner chooses a different merge order. No release publication is authorized or performed.Runnable SQL-free host example:
The example populates a forged cached snapshot, resolves the current target through a composite tenant/identity binding, then changes host target authority and demonstrates parent-preserving nullable denial with an alias/fragment. Public declarations remain the existing GraphQLEntity/GraphQLRelations and Database policy APIs. New doc-hidden runtime helpers support generated code; consumers do not call ORM-private methods or supply query SQL.
Executed verification (jobs=2, line-tables-only debug, incremental=0, disk-backed TMPDIR/target caches):
cargo test --manifest-path crates/graphql-orm-macros/fixtures/cross-crate-relations/Cargo.toml --locked -p cross-crate-source-models --no-default-features --features sqlite: 6 tests passed. The separate--features postgrescommand also has 6 passed, using only labelled disposable test-owned containers with ownership-checked cleanup. One generated illustrative search doctest is ignored in each lane; no backend execution tests are ignored.cargo test -p graphql-orm --locked --no-default-features --features sqlite --lib --test authorization_mode --test composite_relations --test conditional_relations --test recursive_relations --test computed_order_and_complex_relations --test bidirectional_join_relations --test authorized_pagination: 54 passed, one pre-existing large release-mode pagination benchmark ignored.cargo test -p graphql-orm-macros --locked --no-default-features --features sqlite --lib: 6 passed.sqlite,postgres,mssql: passed. MSSQL is compile-only, no live MSSQL execution claimed.bash scripts/check-package-release-policy.sh 4617b332014758387a3c271a7b30a5aff4873453andbash scripts/check-semver.sh 4617b332014758387a3c271a7b30a5aff4873453: passed. Never workspace all-features.Known limits: callbacks requiring exact complete counts must finish within the host scan budget; SQL-complete policies are the bounded batched path. Explicit bulk snapshots are no longer reused for GraphQL authority. Other application loader cache types are not authoritative and trigger fresh-query fallback. Scope guards remain host-owned; no credentials, transport authority, policy language, sibling changes, data migration or releases.
Documentation impact: current generated relationship authority contract, migration/compatibility notes, changelog, SQL-free executable example and generated package inventory. Additional static query/group/private-view requirements remain independent workstreams in #91.
Additional explicit compatibility evidence:
cargo semver-checks -p graphql-orm --manifest-path crates/graphql-orm/Cargo.toml --baseline-root <owned-4617b33-baseline>/crates/graphql-orm --default-features --release-type patchactually builds/parses 0.33.4 and 0.33.5 and passes 223 checks (30 inapplicable checks skipped). Issue #100 separately tracks no-analysis invocation behavior without explicit package selection. The reviewable implementation head remains unchanged.