2.0: Standard Schema validation for query/action input
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
- Issue type
- Feature
- Clarity
- Needs clarification
- Activity status
- Quiet
- Tech stack
- typescript
- Domain
- api, backend-api-design
Research direction
Start by reading the actionable context in #507 and its linked server-function constraint discussion, then review the existing query and action APIs alongside the Standard Schema contract. The open questions about overload shape, multi-argument functions, validation failures, and direct server-side calls must be resolved before implementation is complete.
Written by the indexing model from the issue text.
Description
Tracking the actionable part of #507 as a 2.0 improvement.
Problem
"use server" functions type their arguments as written (e.g. email: string), but the input actually crosses a serialization boundary and is attacker-controlled. Typing it honestly as unknown destroys caller-side DX. Users want "typed on the outside, validated on the inside."
Userland wrappers can't solve this: composing a validator around a "use server" function runs into server-function compilation constraints (Server Functions cannot be nested in other blocks or functions - see https://github.com/solidjs/solid-router/issues/507#issuecomment-2694797871), so first-class router support is the only clean path.
Proposal
Accept an optional Standard Schema validator in query and action:
const getUser = query(z.string().email(), async (email) => {
"use server";
// email: string, already validated at the boundary
}, "get-user");
- Caller-side argument types derive from the schema's input type.
- The function body receives the schema's output type, validated server-side before the body runs.
- Standard Schema keeps the router decoupled from any particular validation library (Zod, Valibot, ArkType all implement it), same approach TanStack Router took.
Open design questions:
- Overload shape (
query(schema, fn, name)vs options object) and how it interacts with multi-argument functions. - Validation failure behavior (throw a typed error? 400-style response for actions?).
- Whether validation also runs on direct server-side calls or only across the RPC boundary.
Refs #507
- Dominant language
- TypeScript
- Stars
- 1.3k
- Forks
- 180
- Avg merge
- 1d 6h
- Merged PRs (30d)
- 20
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from solidjs/solid-router
-
Difficulty 3/5 1-2 days Newbie friendliness 74/100
solidjs/solid-router#624 ·
Maintainers usually reply within 1 day
-
<A> costs ~6us of server CPU per instance during SSR (20x a plain <a>), mostly mergeProps/splitPropsOpen
Difficulty 4/5 3-5 days Newbie friendliness 55/100
solidjs/solid-router#583 ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 38/100
solidjs/solid-router#518 · 2 comments ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 64/100
solidjs/solid-router#502 · 4 comments ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
solidjs/solid-router#482 · 2 comments ·
Maintainers usually reply within 1 day
All issues in solidjs/solid-router
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
melgarafael/DeskcommCRM#1812 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
prisma/prisma-cli#309 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
gregwebs/pi-quota-dispatcher#26 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
openwatersio/slackwater.xyz#124 ·
Maintainers usually reply within 1 day
-
agent-reported area/browser area/docs documentation good first issue hacktoberfest help wanted P2
Difficulty 1/5 Under an hour Newbie friendliness 90/100
Maintainers usually reply within 2 days