/installations and /audiences reject a find sent as POST + _method=GET with "Invalid key name: 0"
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 2/5
- 見積もり時間
- 半日
- 初心者へのやさしさ
- 65/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 静か
- 技術スタック
- javascript, nodejs
調査の方向性
まず、src/Routers/InstallationsRouter.js と src/Routers/AudiencesRouter.js を ClassesRouter.handleFind と比較し、リクエストボディから値を取得する文字列がどのように処理されるかに注目してください。両方のルートに対して curl method-override reproducer を使用し、リクエストが Invalid key name: 0 ではなくクエリ結果を返すことを確認してください。
索引モデルが issue の本文から書いたものです。
説明
New Issue Checklist
- Report security issues confidentially.
- Any contribution is under this license.
- Before posting search existing issues.
Issue Description
InstallationsRouter.handleFind and AudiencesRouter.handleFind override ClassesRouter.handleFind but drop its string-where decoding step, so a query sent with the documented POST + _method=GET override fails on /installations and /audiences while the identical query succeeds on /classes/_Installation.
ClassesRouter.handleFind decodes a where that arrives in the request body as a JSON string:
if (typeof body.where === 'string') {
try {
body.where = JSON.parse(body.where);
} catch {
throw new Parse.Error(Parse.Error.INVALID_JSON, 'where parameter is not valid JSON');
}
}
The two subclasses copy the body/options lines but not that block, so they only handle a where that arrives in the query string (decoded by ClassesRouter.JSONFromQuery). When the client uses the method override with an application/x-www-form-urlencoded body, body.where stays a string and is passed straight to rest.find. DatabaseController.validateQuery then runs Object.keys() over the string, walking it character by character, and the first index fails the key-name regex:
{"code":105,"error":"Invalid key name: 0"}
This is the same failure mode as the AggregateRouter pipeline handling that produced Invalid aggregate stage '0'.
The trigger is query size, not query shape. SDKs switch from GET to POST + _method=GET once the URL exceeds ~2 KB, so this only appears when an app queries /installations with a large enough constraint, for example an installationId $in list of roughly 41 or more ids. The same code path works for /users, /roles and /sessions, whose routers inherit ClassesRouter.handleFind unchanged.
Steps to reproduce
Any query long enough for the SDK to use the method override reproduces this. A minimal equivalent with curl:
# 1. POST + _method=GET against /installations -> error 105
curl -s -X POST \
-H 'X-Parse-Application-Id: myAppId' \
-H 'X-Parse-Master-Key: myMasterKey' \
-H 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode '_method=GET' \
--data-urlencode 'where={"installationId":{"$in":["af593bd0-cede-4b27-b0d0-1b48a025dc03"]}}' \
--data-urlencode 'limit=100' \
http://localhost:1337/parse/installations
# 2. Identical request against /classes/_Installation -> succeeds
curl -s -X POST \
-H 'X-Parse-Application-Id: myAppId' \
-H 'X-Parse-Master-Key: myMasterKey' \
-H 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode '_method=GET' \
--data-urlencode 'where={"installationId":{"$in":["af593bd0-cede-4b27-b0d0-1b48a025dc03"]}}' \
--data-urlencode 'limit=100' \
http://localhost:1337/parse/classes/_Installation
# 3. Same where as a GET query string against /installations -> succeeds
curl -s -G \
-H 'X-Parse-Application-Id: myAppId' \
-H 'X-Parse-Master-Key: myMasterKey' \
--data-urlencode 'where={"installationId":{"$in":["af593bd0-cede-4b27-b0d0-1b48a025dc03"]}}' \
http://localhost:1337/parse/installations
/audiences fails the same way.
Actual Outcome
1. {"code":105,"error":"Invalid key name: 0"}
2. {"results":[]}
3. {"results":[]}
Expected Outcome
All three return the query results. The method override is supported transport for a find, so /installations and /audiences should decode a string where from the body exactly as /classes/:className does.
Environment
Server
- Parse Server version:
9.10.0(also present onalphaat9.10.1-alpha.6;src/Routers/InstallationsRouter.jsandsrc/Routers/AudiencesRouter.jsare unchanged there) - Operating system:
macOS 15.5 (Docker, node:22 image) - Local or remote host:
local
Database
- System (MongoDB or Postgres):
MongoDB - Database version:
7.0.31 - Local or remote host:
local
Client
- SDK (iOS, Android, JavaScript, PHP, Unity, etc):
reproduced with curl; originally hit from the Ruby SDK - SDK version:
parse-stack-next 5.7.0
Logs
error: Invalid key name: 0 {"code":105,"stack":"Error: Invalid key name: 0
at .../parse-server/lib/Controllers/DatabaseController.js:208:13
at Array.forEach (<anonymous>)
at validateQuery (.../parse-server/lib/Controllers/DatabaseController.js:190:22)
at .../parse-server/lib/Controllers/DatabaseController.js:1238:11
at async _UnsafeRestQuery.runFind (.../parse-server/lib/RestQuery.js:785:19)"}
{"method":"POST","objectId":null,"body":{"keys":"installationId,appBuildNumber,appVersion","limit":"100","skip":"0","where":"{\"installationId\":{\"$in\":[\"af593bd0-cede-4b27-b0d0-1b48a025dc03\", ...]}}"},"installationId":null,"statusCode":400}
The logged body.where is still a string at the point the error is raised, which is the tell: ClassesRouter.handleFind mutates req.body.where into an object in place, so a request that went through the classes route would show a decoded object here.
I have a fix and can open a PR against alpha.
- 主要言語
- JavaScript
- スター
- 21.4k
- フォーク
- 4.8k
- 平均マージ
- 2日 12分
- マージ済み PR(30日)
- 47
環境構築
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
parse-community/parse-server のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
parse-community/parse-server#10720 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
parse-community/parse-server#10710 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 92/100
parse-community/parse-server#10699 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
parse-community/parse-server#10634 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 84/100
parse-community/parse-server#10631 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
parse-community/parse-server の issue をすべて見る
似ている issue
-
feature task
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
RealDevSquad/website-www#1178 ·
-
add latest sol modelオープン
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
netlify-labs/nax#56 · コメント 2 件 · リアクション 1 件 ·
-
accessibility bug revealjs
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
quarto-dev/quarto-cli#14961 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
PnX-SI/GeoNature#4435 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
openlayers/openlayers#17648 ·
メンテナーはふだん 1 日以内に返信