Repository navigation
Add ParserOptions.Trusted for server-produced and persisted documents - #10241
Merged
Merged
Conversation
Contributor
There was a problem hiding this comment.
Pull request overview
This PR introduces a new ParserOptions.Trusted preset intended for server-controlled GraphQL documents (persisted operations and server-produced/rewritten documents) and wires it through Fusion + persisted-operation storage/pipeline parsing to avoid false failures on the default 2,048-field guard during internal re-parsing.
Changes:
- Add
ParserOptions.Trustedand tests covering lifted field-count limits while keeping recursion depth protection. - Use
ParserOptions.Trustedwhen parsing persisted operation documents across FileSystem/Redis/AzureBlob + persisted-operation pipeline. - Use
ParserOptions.Trustedwhen parsing server-produced operation text in Fusion execution plan parsing and execution nodes; add a planner regression test.
Reviewed changes
Copilot reviewed 16 out of 16 changed files in this pull request and generated 2 comments.
Show a summary per file
| File | Description |
|---|---|
| src/HotChocolate/PersistedOperations/test/PersistedOperations.FileSystem.Tests/IntegrationTests.cs | Adds integration coverage for executing a persisted operation whose field count exceeds the default request parser limit. |
| src/HotChocolate/PersistedOperations/src/PersistedOperations.Redis/RedisOperationDocumentStorage.cs | Parses Redis-stored persisted operations with ParserOptions.Trusted. |
| src/HotChocolate/PersistedOperations/src/PersistedOperations.Pipeline/Execution/Pipeline/ReadPersistedOperationMiddleware.cs | Parses stored persisted-operation documents with ParserOptions.Trusted when a syntax node isn’t already provided. |
| src/HotChocolate/PersistedOperations/src/PersistedOperations.FileSystem/FileSystemOperationDocumentStorage.cs | Parses filesystem persisted operations with ParserOptions.Trusted. |
| src/HotChocolate/PersistedOperations/src/PersistedOperations.AzureBlobStorage/AzureBlobOperationDocumentStorage.cs | Parses blob-stored persisted operations with ParserOptions.Trusted. |
| src/HotChocolate/Language/test/Language.Tests/Parser/QueryParserTests.cs | Adds unit tests validating ParserOptions.Trusted behavior for field-count and recursion-depth limits. |
| src/HotChocolate/Language/src/Language.Utf8/ParserOptions.cs | Introduces ParserOptions.Trusted preset. |
| src/HotChocolate/Fusion/test/Fusion.Execution.Tests/Planning/PlannerBehaviorTests.cs | Adds regression coverage for planning when fragment expansion exceeds the default field limit. |
| src/HotChocolate/Fusion/src/Fusion.Execution/Execution/Nodes/Serialization/JsonOperationPlanParser.cs | Parses operation documents from JSON plans with ParserOptions.Trusted. |
| src/HotChocolate/Fusion/src/Fusion.Execution/Execution/Nodes/OperationExecutionNode.cs | Parses operation source with ParserOptions.Trusted when constructing execution nodes. |
| src/HotChocolate/Fusion/src/Fusion.Execution/Execution/Nodes/OperationDefinition.cs | Parses operation source with ParserOptions.Trusted when constructing plan operation definitions. |
| src/HotChocolate/Fusion/src/Fusion.Execution/Execution/Nodes/ApolloOperationExecutionNode.cs | Uses ParserOptions.Trusted when parsing rewritten/lookup operation source. |
| src/HotChocolate/Fusion/src/Fusion.Execution/Execution/Nodes/ApolloOperationBatchExecutionNode.cs | Uses ParserOptions.Trusted when parsing rewritten/lookup operation source in batch execution. |
| src/HotChocolate/Fusion/src/Fusion.Execution/Execution/ApolloFederation/RepresentationShapeBuilder.cs | Parses operation source with ParserOptions.Trusted while building representation shape bindings. |
| src/HotChocolate/Fusion/src/Fusion.Execution/Execution/ApolloFederation/LookupEntityQueryRewriter.cs | Parses operation source with ParserOptions.Trusted prior to rewriting into _entities query. |
| src/HotChocolate/Fusion/src/Fusion.Connectors.InMemory/InMemorySourceSchemaClient.cs | Parses in-process operation source with ParserOptions.Trusted to avoid re-parse guard failures. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Contributor
This was referenced Aug 29, 2026
Merged
This was referenced Sep 8, 2026
Closed
Closed
This was referenced Sep 15, 2026
Closed
[nuget][SUI_Matcher]- Bump the sui-package-updates group with 20 updates
DFE-Digital/SUI_Matcher#405
Closed
Closed
This was referenced Sep 22, 2026
Closed
Closed
[nuget][SUI_Matcher]- Bump the sui-package-updates group with 20 updates
DFE-Digital/SUI_Matcher#410
Merged
This was referenced Oct 5, 2026
Open
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #10223