Skip to content

Add ParserOptions.Trusted for server-produced and persisted documents - #10241

Merged
michaelstaib merged 4 commits into
mainfrom
mst/trusted-parser-options
Aug 16, 2026
Merged

michaelstaib merged 4 commits into
mainfrom
mst/trusted-parser-options

Conversation

@michaelstaib

Copy link
Copy Markdown
Member

Fixes #10223

Copilot AI lite review requested due to automatic review settings August 16, 2026 09:09

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR introduces a new ParserOptions.Trusted preset intended for server-controlled GraphQL documents (persisted operations and server-produced/rewritten documents) and wires it through Fusion + persisted-operation storage/pipeline parsing to avoid false failures on the default 2,048-field guard during internal re-parsing.

Changes:

  • Add ParserOptions.Trusted and tests covering lifted field-count limits while keeping recursion depth protection.
  • Use ParserOptions.Trusted when parsing persisted operation documents across FileSystem/Redis/AzureBlob + persisted-operation pipeline.
  • Use ParserOptions.Trusted when parsing server-produced operation text in Fusion execution plan parsing and execution nodes; add a planner regression test.

Reviewed changes

Copilot reviewed 16 out of 16 changed files in this pull request and generated 2 comments.

Show a summary per file
File Description
src/HotChocolate/PersistedOperations/test/PersistedOperations.FileSystem.Tests/IntegrationTests.cs Adds integration coverage for executing a persisted operation whose field count exceeds the default request parser limit.
src/HotChocolate/PersistedOperations/src/PersistedOperations.Redis/RedisOperationDocumentStorage.cs Parses Redis-stored persisted operations with ParserOptions.Trusted.
src/HotChocolate/PersistedOperations/src/PersistedOperations.Pipeline/Execution/Pipeline/ReadPersistedOperationMiddleware.cs Parses stored persisted-operation documents with ParserOptions.Trusted when a syntax node isn’t already provided.
src/HotChocolate/PersistedOperations/src/PersistedOperations.FileSystem/FileSystemOperationDocumentStorage.cs Parses filesystem persisted operations with ParserOptions.Trusted.
src/HotChocolate/PersistedOperations/src/PersistedOperations.AzureBlobStorage/AzureBlobOperationDocumentStorage.cs Parses blob-stored persisted operations with ParserOptions.Trusted.
src/HotChocolate/Language/test/Language.Tests/Parser/QueryParserTests.cs Adds unit tests validating ParserOptions.Trusted behavior for field-count and recursion-depth limits.
src/HotChocolate/Language/src/Language.Utf8/ParserOptions.cs Introduces ParserOptions.Trusted preset.
src/HotChocolate/Fusion/test/Fusion.Execution.Tests/Planning/PlannerBehaviorTests.cs Adds regression coverage for planning when fragment expansion exceeds the default field limit.
src/HotChocolate/Fusion/src/Fusion.Execution/Execution/Nodes/Serialization/JsonOperationPlanParser.cs Parses operation documents from JSON plans with ParserOptions.Trusted.
src/HotChocolate/Fusion/src/Fusion.Execution/Execution/Nodes/OperationExecutionNode.cs Parses operation source with ParserOptions.Trusted when constructing execution nodes.
src/HotChocolate/Fusion/src/Fusion.Execution/Execution/Nodes/OperationDefinition.cs Parses operation source with ParserOptions.Trusted when constructing plan operation definitions.
src/HotChocolate/Fusion/src/Fusion.Execution/Execution/Nodes/ApolloOperationExecutionNode.cs Uses ParserOptions.Trusted when parsing rewritten/lookup operation source.
src/HotChocolate/Fusion/src/Fusion.Execution/Execution/Nodes/ApolloOperationBatchExecutionNode.cs Uses ParserOptions.Trusted when parsing rewritten/lookup operation source in batch execution.
src/HotChocolate/Fusion/src/Fusion.Execution/Execution/ApolloFederation/RepresentationShapeBuilder.cs Parses operation source with ParserOptions.Trusted while building representation shape bindings.
src/HotChocolate/Fusion/src/Fusion.Execution/Execution/ApolloFederation/LookupEntityQueryRewriter.cs Parses operation source with ParserOptions.Trusted prior to rewriting into _entities query.
src/HotChocolate/Fusion/src/Fusion.Connectors.InMemory/InMemorySourceSchemaClient.cs Parses in-process operation source with ParserOptions.Trusted to avoid re-parse guard failures.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/HotChocolate/Language/src/Language.Utf8/ParserOptions.cs
@github-actions

github-actions Bot commented Aug 16, 2026 •

Copy link
Copy Markdown
Contributor

Patch coverage

95.5% of changed lines covered (21/22)

File Covered Changed Patch %
…/Execution/Pipeline/ReadPersistedOperationMiddleware.cs 0 1 0.0% 🔴
…/src/Fusion.Connectors.InMemory/InMemorySourceSchemaClient.cs 4 4 100.0% 🟢
…/Execution/ApolloFederation/LookupEntityQueryRewriter.cs 1 1 100.0% 🟢
…/Execution/ApolloFederation/RepresentationShapeBuilder.cs 1 1 100.0% 🟢
…/Execution/Nodes/ApolloOperationBatchExecutionNode.cs 1 1 100.0% 🟢
…/Execution/Nodes/ApolloOperationExecutionNode.cs 2 2 100.0% 🟢
…/src/Fusion.Execution/Execution/Nodes/OperationDefinition.cs 1 1 100.0% 🟢
…/Fusion.Execution/Execution/Nodes/OperationExecutionNode.cs 1 1 100.0% 🟢
…/Execution/Nodes/Serialization/JsonOperationPlanParser.cs 2 2 100.0% 🟢
src/HotChocolate/Language/src/Language.Utf8/ParserOptions.cs 5 5 100.0% 🟢
…/AzureBlobOperationDocumentStorage.cs 1 1 100.0% 🟢
…/FileSystemOperationDocumentStorage.cs 1 1 100.0% 🟢
…/PersistedOperations.Redis/RedisOperationDocumentStorage.cs 1 1 100.0% 🟢
Uncovered changed lines (JSON)
{
  "sha": "9ff24260506743a3fa9f9c4bed8a6749e9a5fc58",
  "files": [
    { "path": "src/HotChocolate/PersistedOperations/src/PersistedOperations.Pipeline/Execution/Pipeline/ReadPersistedOperationMiddleware.cs", "ranges": [[83, 83]] }
  ]
}

Project coverage: 54.5% (243368/446634 lines)

@michaelstaib
michaelstaib merged commit e256ff0 into main Aug 16, 2026
149 checks passed
@michaelstaib
michaelstaib deleted the mst/trusted-parser-options branch August 16, 2026 12:24
This was referenced Aug 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

2 participants