bug: malformed JSON passed to --document (and other body object flags) silently passes validation
I maintainer di solito rispondono entro 1 giorno
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 74/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- typescript
- Ambito
- cli
Direzione di ricerca
Start in src/factory.ts around the object-flag parsing near line 609 and schema relaxation near line 700. Reproduce the elastic stack es index command with the malformed --document value, then trace how JSON.parse failures reach validation. Done means the command reports an input_validation_failed error for invalid JSON and exits 1 instead of printing a successful dry-run payload.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Description
Running the following command reports success for inputs that are valid, but the JSON is malformed:
elastic stack es index \
--index test-idx \
--document '{"name":"Alice"invalid}' \
--dry-run
The command exits 0 and prints the resolved request payload without any validation error, even though {"name":"Alice"invalid} is not valid JSON.
Root cause
There are two cooperating bugs in src/factory.ts.
Bug 1 — silent catch in object-flag parsing (≈ line 609)
When a CLI flag is typed as object and JSON.parse fails, the catch block silently falls back to storing the raw string:
} else if (arg.type === 'object') {
try {
const parsed = JSON.parse(raw as string)
cliInput[arg.schemaKey] = parsed
...
} catch {
// If JSON parse fails, pass the raw value - handles schema-less fields
// that accept plain strings (e.g. connector update-error --error)
cliInput[arg.schemaKey] = raw // ← malformed JSON stored as string
}
}
The comment's rationale ("schema-less fields that accept plain strings") does not apply to --document, which is explicitly typed as object in the Elasticsearch index API schema. There is no connector update-error command in the current codebase, so the comment appears stale.
Bug 2 — schema relaxed to {} before AJV validation (≈ line 700)
Even if Bug 1 were fixed and the raw string reached validation, the validator would still accept it because body fields with type === 'object' have their JSON Schema replaced with {} (accept anything) before AJV runs:
const relaxFields = schemaArgs.filter(
(a) =>
sortParsedKeys.has(a.schemaKey) ||
(a.foundIn === 'body' && (a.type === 'object' || a.type === 'array'))
)
// ...
props[f.schemaKey] = {} // ← accepts any value, including a malformed-JSON string
The relaxation exists to avoid false positives for complex Elasticsearch DSL bodies (e.g. query, _source), but it also suppresses the type error introduced by Bug 1.
Proposed fix
Fix Bug 1: When JSON.parse throws for an object-typed flag, emit an input_validation_failed error immediately instead of falling back to the raw string. The silent fallback was added for a use case that no longer exists.
Fix Bug 2 (optional / complementary): The schema relaxation for body object fields is a blunt instrument. A narrower approach would be to only relax fields that come from user-provided structured DSL (e.g. query, aggs), not scalar-like fields such as document. In the short term, fixing Bug 1 is sufficient to surface the error before validation is reached.
Expected behaviour
elastic stack es index --index test-idx --document '{"name":"Alice"invalid}' --dry-run
# Error: --document: invalid JSON: ...
# exit 1
Actual behaviour
Command exits 0 and prints the dry-run payload as if the input were valid.
authored by Pi Coding Agent (Claude Sonnet 4.5)
- Lingua principale
- TypeScript
- Stelle
- 47
- Fork
- 27
- Merge medio
- 2g 3h
- PR unite (30g)
- 55
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di elastic/cli
-
feat: ship skills/elastic/SKILL.md for agent invocationForse già presa @onatozmenn l’ha presa 13 giorni fa. Apertaenhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
elastic/cli#628 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
elastic/cli#617 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 3/5 Mezza giornata Idoneità per principianti 62/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 20/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 70/100
I maintainer di solito rispondono entro 1 giorno
Issue simili
-
chore v2
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
modelcontextprotocol/servers#5115 ·
I maintainer di solito rispondono entro 1 giorno
-
beginner bug good first issue
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100
philaconvalley/website#168 ·
I maintainer di solito rispondono entro 1 giorno
-
bug frontend good first issue
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
oss-slu/lrda_mobile#294 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
hatchet-dev/hatchet#5179 ·
I maintainer di solito rispondono entro 1 giorno