Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Sanitizing misidentifies diamond-shaped references as cycles

Open
#367 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
57/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Quiet
Tech stack
typescript
Domain
database

Research direction

Reproduce the diamond-shaped create case from the issue, then inspect the inner sanitize method within #sanitizeInitialValues. Verify that sanitizing shared records through both sibling paths leaves both author.profile and editor.profile defined.

Written by the indexing model from the issue text.

Description

This is a very similar issue to #348, but occurs when the same record is referenced from two different paths in a create call.

For example, this code results in the same type of validation error as #348:

import { Collection } from '@msw/data';
import * as v from 'valibot';

const profileSchema = v.object({
  id: v.string(),
  bio: v.string(),
});

const userSchema = v.object({
  id: v.string(),
  name: v.string(),
  get profile() { return profileSchema; },
});

const postSchema = v.object({
  id: v.string(),
  title: v.string(),
  get author() { return userSchema; },
  get editor() { return userSchema; },
});

const profiles = new Collection({ schema: profileSchema });
const users = new Collection({ schema: userSchema });
const posts = new Collection({ schema: postSchema });

users.defineRelations({ one }) => ({ profile: one(profiles) }));
posts.defineRelations({ one }) => ({
  author: one(users),
  editor: one(users),
}));

const profile = await profiles.create({ id: 'p1', bio: 'hi' });
const user = await users.create({ id: 'u1', name: 'Alice', profile });

// Diamond: same user referenced from two sibling fields
await posts.create({
  id: 'post1',
  title: 'Hello',
  author: user,
  editor: user,
});

In this setup, either author.profile or editor.profile will be undefined after sanitization.

From my testing, I've been able to fix the error by adding the following to the inner sanitize method within the #sanitizeInitialValues method:

const result = Object.fromEntries(...);

if (record && !isRevisit) {
  visited.delete(record[kPrimaryKey]);
}

return result;
Dominant language
TypeScript
Stars
1.1k
Forks
66
Avg merge
9m
Merged PRs (30d)
5

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from mswjs/data

All issues in mswjs/data

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.