Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

bug: malformed JSON passed to --document (and other body object flags) silently passes validation

Aperta
#699 1 commento 0 reazioni 1 assegnatario Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

@margaretjgu ci sta già lavorando.

Dal 2/10/2026.

  • #717 di @margaretjgu — aperta

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
74/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
typescript
Ambito
cli

Direzione di ricerca

Start in src/factory.ts around the object-flag parsing near line 609 and schema relaxation near line 700. Reproduce the elastic stack es index command with the malformed --document value, then trace how JSON.parse failures reach validation. Done means the command reports an input_validation_failed error for invalid JSON and exits 1 instead of printing a successful dry-run payload.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

bug

Description

Running the following command reports success for inputs that are valid, but the JSON is malformed:

elastic stack es index \
  --index test-idx \
  --document '{"name":"Alice"invalid}' \
  --dry-run

The command exits 0 and prints the resolved request payload without any validation error, even though {"name":"Alice"invalid} is not valid JSON.

Root cause

There are two cooperating bugs in src/factory.ts.

Bug 1 — silent catch in object-flag parsing (≈ line 609)

When a CLI flag is typed as object and JSON.parse fails, the catch block silently falls back to storing the raw string:

} else if (arg.type === 'object') {
  try {
    const parsed = JSON.parse(raw as string)
    cliInput[arg.schemaKey] = parsed
    ...
  } catch {
    // If JSON parse fails, pass the raw value - handles schema-less fields
    // that accept plain strings (e.g. connector update-error --error)
    cliInput[arg.schemaKey] = raw   // ← malformed JSON stored as string
  }
}

The comment's rationale ("schema-less fields that accept plain strings") does not apply to --document, which is explicitly typed as object in the Elasticsearch index API schema. There is no connector update-error command in the current codebase, so the comment appears stale.

Bug 2 — schema relaxed to {} before AJV validation (≈ line 700)

Even if Bug 1 were fixed and the raw string reached validation, the validator would still accept it because body fields with type === 'object' have their JSON Schema replaced with {} (accept anything) before AJV runs:

const relaxFields = schemaArgs.filter(
  (a) =>
    sortParsedKeys.has(a.schemaKey) ||
    (a.foundIn === 'body' && (a.type === 'object' || a.type === 'array'))
)
// ...
props[f.schemaKey] = {}   // ← accepts any value, including a malformed-JSON string

The relaxation exists to avoid false positives for complex Elasticsearch DSL bodies (e.g. query, _source), but it also suppresses the type error introduced by Bug 1.

Proposed fix

Fix Bug 1: When JSON.parse throws for an object-typed flag, emit an input_validation_failed error immediately instead of falling back to the raw string. The silent fallback was added for a use case that no longer exists.

Fix Bug 2 (optional / complementary): The schema relaxation for body object fields is a blunt instrument. A narrower approach would be to only relax fields that come from user-provided structured DSL (e.g. query, aggs), not scalar-like fields such as document. In the short term, fixing Bug 1 is sufficient to surface the error before validation is reached.

Expected behaviour

elastic stack es index --index test-idx --document '{"name":"Alice"invalid}' --dry-run
# Error: --document: invalid JSON: ...
# exit 1

Actual behaviour

Command exits 0 and prints the dry-run payload as if the input were valid.


authored by Pi Coding Agent (Claude Sonnet 4.5)

Lingua principale
TypeScript
Stelle
47
Fork
27
Merge medio
2g 3h
PR unite (30g)
55

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di elastic/cli

Tutte le issue di elastic/cli

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.