Skip to content

DynamicParameters.AddParameters(IDbCommand): identity-free self-apply - #2225

Merged
mgravell merged 2 commits into
mainfrom
dynamicparameters-apply
Aug 20, 2026
Merged

DynamicParameters.AddParameters(IDbCommand): identity-free self-apply#2225
mgravell merged 2 commits into
mainfrom
dynamicparameters-apply

Conversation

@mgravell

Copy link
Copy Markdown
Member

The full bag protocol — per-parameter DbType/direction/size/precision/scale, templates, literal replacement, RemoveUnused — already lives in AddParameters(command, identity), but the identity requirement makes it uncallable from outside: Identity's constructor is internal, and identity.Sql is consumed on the first line. This overload builds the identity from the command's own text and type (which is what identity.Sql is in practice), letting external tooling apply a parameter bag without reimplementing the protocol.

The immediate consumer is Dapper.AOT: its generated command factories can now support DynamicParameters arguments by delegating to the bag itself — which gives exact vanilla behavior for the whole surface (including Get<T> output reads and IParameterCallbacks) because it is the vanilla implementation. The generator probes for this symbol, so it activates only when the referenced Dapper has it; no coordination needed on release timing.

Test covers the bag + literal-replacement composition against a closed connection (no database needed). API registered in PublicAPI.Unshipped.txt.

The full bag protocol (per-parameter DbType/direction/size, templates,
literal replacement, RemoveUnused) already lives in AddParameters(command,
identity), but the identity requirement makes it uncallable from outside:
Identity's constructor is internal, and identity.Sql is consumed on the
first line. This overload builds the identity from the command's own text
and type, which is what identity.Sql is in practice - letting external
tooling (for example build-time code generators, aka Dapper.AOT) apply a
bag without reimplementing the protocol.

Test covers the bag+literal composition against a closed connection (no
database needed).
A subclass that hides AddParameters and re-implements the interface - the
DynamicParameterWithIntTVP pattern from this very test suite - was skipped
by the direct call, which binds statically to the protected base method.
Routing through the interface uses the runtime type's interface map, so
the subclass version runs, matching what vanilla execution does.
@mgravell

Copy link
Copy Markdown
Member Author

Pushed a follow-up: the overload now dispatches via (SqlMapper.IDynamicParameters)this rather than calling the protected method directly. A subclass that hides AddParameters and re-implements the interface — the DynamicParameterWithIntTVP pattern from this repo's own test suite — was otherwise skipped, because the direct call binds statically to the base method. Test added for the hiding-subclass shape.

@mgravell
mgravell merged commit 41d76c7 into main Aug 20, 2026
2 checks passed
This was referenced Sep 12, 2026
This was referenced Sep 14, 2026
github-actions Bot pushed a commit to sloweyyy/cloud-native-ecommerce-platform that referenced this pull request Sep 14, 2026
Updated [Dapper](https://github.com/DapperLib/Dapper) from 2.1.79 to
2.1.86.

<details>
<summary>Release notes</summary>

_Sourced from [Dapper's
releases](https://github.com/DapperLib/Dapper/releases)._

## 2.1.86

## What's Changed
* Point docs links at dapperlib.dev by @​mgravell in
DapperLib/Dapper#2222
* Point PackageReleaseNotes at GitHub Releases by @​mgravell in
DapperLib/Dapper#2223
* Pin the docs site config, and give it a favicon by @​mgravell in
DapperLib/Dapper#2224
* DynamicParameters.AddParameters(IDbCommand): identity-free self-apply
by @​mgravell in DapperLib/Dapper#2225
* Re-enable DateOnly/TimeOnly support, fixing the defects that got it
disabled by @​mgravell in DapperLib/Dapper#2228
* Publish to nuget.org via Trusted Publishing (OIDC), and retire
MyGet/AppVeyor by @​mgravell in
DapperLib/Dapper#2230


**Full Changelog**:
DapperLib/Dapper@2.1.79...2.1.86

Commits viewable in [compare
view](DapperLib/Dapper@2.1.79...2.1.86).
</details>

Updated
[Microsoft.Extensions.Configuration.Abstractions](https://github.com/dotnet/dotnet)
from 10.0.11 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Extensions.Configuration.Abstractions's
releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare
view](https://github.com/dotnet/dotnet/commits).
</details>

Updated
[Microsoft.Extensions.Configuration.Binder](https://github.com/dotnet/dotnet)
from 10.0.11 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Extensions.Configuration.Binder's
releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare
view](https://github.com/dotnet/dotnet/commits).
</details>

Updated
[Microsoft.Extensions.DependencyInjection.Abstractions](https://github.com/dotnet/dotnet)
from 10.0.11 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Extensions.DependencyInjection.Abstractions's
releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare
view](https://github.com/dotnet/dotnet/commits).
</details>

Updated
[Microsoft.Extensions.Hosting.Abstractions](https://github.com/dotnet/dotnet)
from 10.0.11 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Extensions.Hosting.Abstractions's
releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare
view](https://github.com/dotnet/dotnet/commits).
</details>

Updated
[Microsoft.Extensions.Logging.Abstractions](https://github.com/dotnet/dotnet)
from 10.0.11 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Extensions.Logging.Abstractions's
releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare
view](https://github.com/dotnet/dotnet/commits).
</details>

Updated [MongoDB.Driver](https://github.com/mongodb/mongo-csharp-driver)
from 3.11.1 to 3.11.2.

<details>
<summary>Release notes</summary>

_Sourced from [MongoDB.Driver's
releases](https://github.com/mongodb/mongo-csharp-driver/releases)._

## 3.11.2

> [!IMPORTANT]
> This is a security patch release. It addresses two CVEs reported
against the driver, along with a small number of related fixes. There
are no public API changes and no application code changes are required
to upgrade. Note that the shape of some queries generated by the LINQ
provider and by GridFS has changed — see the individual tickets below.

This is a patch release that contains fixes and stability improvements:

- [CSHARP-6177](https://jira.mongodb.org/browse/CSHARP-6177) /
[CVE-2026-88026](https://www.cve.org/CVERecord?id=CVE-2026-88026): Query
filter regex injection via unescaped backslash and bracket in LINQ
character-set translation
- [CSHARP-6190](https://jira.mongodb.org/browse/CSHARP-6190) /
[CVE-2026-88025](https://www.cve.org/CVERecord?id=CVE-2026-88025): Use
exact match for file ID in GridFS delete methods
- [CSHARP-6213](https://jira.mongodb.org/browse/CSHARP-6213): Normalize
SRV target host names to lower case during SRV polling

The full list of issues resolved in this release is available at [CSHARP
JIRA
project](https://jira.mongodb.org/issues/?jql=project%20%3D%20CSHARP%20AND%20fixVersion%20%3D%203.11.2%20ORDER%20BY%20key%20ASC).

Documentation on the .NET driver can be found
[here](https://www.mongodb.com/docs/drivers/csharp/v3.11/).

Commits viewable in [compare
view](mongodb/mongo-csharp-driver@v3.11.1...v3.11.2).
</details>

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant