Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Validate ?projectId= references a live project on scoped writes (referential integrity)

Aperta
#1,301 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
48/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Tranquilla
Stack tecnologico
typescript
Ambito
api, backend

Direzione di ricerca

Start at apps/api/src/routes/criteria.ts and trace getQueryProjectId through projectStore.get, then compare the same root-create pattern for profiles, prompt-features, mcp-servers, report-templates, skills, extensions, codebases, and requests. Done means nonexistent project IDs are rejected with 404, soft-deleted IDs are rejected with 409 or handled explicitly, and behavior is consistent across all root-create routes.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Original author: @manekinekko

Context

Surfaced during a data-model review of the per-project data organization work (PR #1241, design #1210).

Scoped write routes resolve the target project from a client-supplied ?projectId= via getQueryProjectId, which only checks that the value is a non-empty string. There is no verification that the id refers to a project that actually exists and is not soft-deleted.

Example: apps/api/src/routes/criteria.ts →

const doc = await getCriteriaStore(projectId).create({ projectId, id, prompt, dependsOn, gates });

The same pattern applies to every root-create route (profiles, criteria, prompt-features, mcp-servers, report-templates, skills, extensions, codebases, requests).

Problem

  • A client can create entities under a non-existent or soft-deleted projectId, producing orphaned rows that no /projects entry owns.
  • projectId is stored as a bare string with no foreign-key guarantee, so nothing at the data layer keeps scoped entities pointing at a live project.
  • Combined with soft-delete being allowed on non-empty projects, data can be created into a project that is already deleted.

Proposed resolution

  • On scoped writes (at minimum root-creates), validate the resolved projectId against projectStore.get(projectId) (excluding soft-deleted) before writing.
  • Reject with 404 (unknown project) or 409 (deleted project) instead of silently writing an orphan.
  • A small in-process cache keeps this cheap on hot paths.
  • Consider whether scoped list/read should likewise treat an unknown/deleted projectId as an error rather than returning an empty set.

Acceptance criteria

  • Creating a scoped entity with a projectId that does not exist is rejected (404).
  • Creating a scoped entity with a soft-deleted projectId is rejected (409) or otherwise handled explicitly.
  • Behavior is consistent across all root-create routes.

Related

  • PR #1241 — per-project data organization
  • Design #1210
  • Related review threads on #1241 (fail-open scoped-store default, double projectId source of truth in CriteriaStore)
Lingua principale
TypeScript
Stelle
5
Fork
5
Merge medio
3g 22h
PR unite (30g)
22

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di microsoft/scope

Tutte le issue di microsoft/scope

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.