Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

[Bug]: allOf in a request body silently drops fields for x-www-form-urlencoded requests

未關閉
#1,212 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

還沒有人認領這個 Issue。

評估

難度
3/5
預估耗時
1-2 天
新手友好度
76/100
Issue 類型
缺陷
描述清晰度
描述清楚
活躍度
冷清
技術堆疊
python
領域
api

研究方向

Start at iter_all_of_schemas in openapi_core/validation/schemas/validators.py and reproduce the form-body example with OpenAPI.from_dict and MockRequest. Verify that the allOf fields are retained and cast as expected, with no silent loss; add a regression test covering the x-www-form-urlencoded request.

由索引模型根據 Issue 內容生成。

描述

kind/bug
Actual Behavior

If a form request body (application/x-www-form-urlencoded) uses allOf, and one of the allOf parts has a field that isn't a string (a boolean, integer,
or object), that whole allOf part gets dropped. Every field in it disappears from the result, even the string ones.

There's no error. result.errors is empty, so it looks like the request succeeded. The fields just silently go missing. A log.warning("invalid allOf schema found") is printed.

In the example below, the result is {'name': 'widget'}. Both enabled (a boolean) and label (a string) are gone, because they're in the same allOf part as the boolean.

Expected Behavior

The result should be {'name': 'widget', 'enabled': True, 'label': 'hello'}.

If I write the same fields as one plain object instead of using allOf, it works correctly and enabled is cast to True:

"schema": {
    "type": "object",
    "properties": {
        "name": {"type": "string"},
        "enabled": {"type": "boolean"},
        "label": {"type": "string"},
    },
}
# -> {'name': 'widget', 'enabled': True, 'label': 'hello'}

allOf should give the same result. And valid data should never be dropped
without an error.

Steps to Reproduce

Run this (only openapi_core is needed):

from openapi_core import OpenAPI
from openapi_core.testing import MockRequest

spec = OpenAPI.from_dict({
    "openapi": "3.0.1",
    "info": {"title": "repro", "version": "1.0.0"},
    "paths": {"/items": {"post": {
        "requestBody": {"content": {"application/x-www-form-urlencoded": {"schema": {
            "allOf": [
                {"$ref": "#/components/schemas/Flags"},
                {"type": "object", "properties": {"name": {"type": "string"}}},
            ]
        }}}},
        "responses": {"200": {"description": "ok"}},
    }}},
    "components": {"schemas": {"Flags": {
        "type": "object",
        "properties": {
            "enabled": {"type": "boolean"},
            "label": {"type": "string"},
        },
    }}},
})

request = MockRequest(
    host_url="http://example.com", method="post", path="/items",
    data=b"name=widget&label=hello&enabled=true",
    content_type="application/x-www-form-urlencoded",
)
result = spec.unmarshal_request(request)
print(result.body)     # {'name': 'widget'}
print(result.errors)   # []

Output:

invalid allOf schema found
{'name': 'widget'}
[]
OpenAPI Core Version

0.23.1

OpenAPI Core Integration

none (openapi_core.testing.MockRequest); first seen with Django

Affected Area(s)

unmarshalling, schema

References

This looks related to the older "allOf is treated as type: any" reports (#147, #149), but here the effect is different: valid data is silently dropped,
instead of just a confusing error message. It only happens for form bodies, where values arrive as strings.

It seems to come from iter_all_of_schemas in openapi_core/validation/schemas/validators.py. Each allOf part is checked against the raw value and skipped if it doesn't match. For form bodies the values are still strings at that point, so a part with enabled: {type: boolean} fails against the string "true", gets skipped, and its fields are never read.

Anything else we need to know?

No response

Would you like to implement a fix?

Yes

主要語言
Python
星號
368
分支
140
PR 合併指標
30 天內沒有已合併 PR

環境準備

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

python-openapi/openapi-core 的其他 Issue

查看 python-openapi/openapi-core 的全部 Issue

相似的 Issue

更多 Python Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。