Conversation
A property path inside an arithmetic expression did not go through the property resolver, so MaxPropertyDepth did not apply to it. A caller could reach deeper navigation properties than the limit permits, for example (Recipe.Rating + 0) > 1 with a limit of 0. Resolve each property in an arithmetic expression, so the depth check applies. BREAKING CHANGE: a filter with an arithmetic property path deeper than MaxPropertyDepth now throws QueryKitPropertyDepthExceededException.
pdevito3
force-pushed
the
fm/qk-breaking-arithmetic-depth
branch
from
October 1, 2026 21:46
aa341d8 to
7cfed06
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
For later consideration in a major version. Do not merge now. #134 removed this check to keep v1.x compatible with v1.14.2 (restore commit
8a09c25). This PR re-applies the depth part of988fdff(#113). The captain decides on this PR separately.Summary
ResolveArithmeticPropertiessends each property path in an arithmetic expression throughPropertyResolver.Resolve.ResolveappliesMaxPropertyDepthand theHasMaxDepthoverrides, like for every other property path.Scope: this PR changes only the depth check.
PropertyResolveron main does not map query names, so a query name in arithmetic still throws, as on main. That is item J-bis, in #154.PreventFilterin arithmetic is item I (#136). The rewrite to the member path changes only the letter case, and arithmetic already ignores the case.v1.14.2 behavior (and main)
A property path inside arithmetic skips the depth check. Every other property path in a filter or a sort obeys
MaxPropertyDepth.New behavior
A property path inside arithmetic obeys
MaxPropertyDepthtoo. A path that is too deep throwsQueryKitPropertyDepthExceededException.Example
Recipe.QueryKitPropertyDepthExceededException.Recipe.Rating == 1without arithmetic already throws on v1.14.2.Security risk on v1.14.2
MaxPropertyDepthlimits how deep a caller can go into the object graph. With arithmetic, a caller skips the limit:(Recipe.Rating + 0) > 1passes a limit of 0. A caller can then filter on related data that the limit was set to block, and can make larger joins than the app permits.Justification
The limit must apply to every property path, or it does not limit anything. Arithmetic was the only path that skipped it.
Migration
If a filter needs a deeper arithmetic path, increase
MaxPropertyDepth, or addHasMaxDepthon the property.README
The Max Property Depth section now tells that the limit also applies to a property path inside an arithmetic expression.
Tests
This test comes back from main before #134, in
PropertyResolverTests:arithmetic_property_skips_max_property_depth->arithmetic_property_obeys_max_property_depthdotnet test: 470 unit tests and 297 Postgres integration tests (Testcontainers) pass, 0 failures.Rebase on main
This branch is rebased on current main (#169). The rebase had no conflicts. The breaking change did not change.
Interaction with #151 (item O)
#151 (item O) adds an unknown-property check to the arithmetic
Select. If both merge, the second one gets a text conflict. The combined code is theResolveArithmeticPropertiesof main before #134, with the depth check and the unknown-property check.