DynamicParameters.AddParameters(IDbCommand): identity-free self-apply - #2225
Merged
Conversation
The full bag protocol (per-parameter DbType/direction/size, templates, literal replacement, RemoveUnused) already lives in AddParameters(command, identity), but the identity requirement makes it uncallable from outside: Identity's constructor is internal, and identity.Sql is consumed on the first line. This overload builds the identity from the command's own text and type, which is what identity.Sql is in practice - letting external tooling (for example build-time code generators, aka Dapper.AOT) apply a bag without reimplementing the protocol. Test covers the bag+literal composition against a closed connection (no database needed).
This was referenced Aug 18, 2026
A subclass that hides AddParameters and re-implements the interface - the DynamicParameterWithIntTVP pattern from this very test suite - was skipped by the direct call, which binds statically to the protected base method. Routing through the interface uses the runtime type's interface map, so the subclass version runs, matching what vanilla execution does.
Member
Author
|
Pushed a follow-up: the overload now dispatches via |
This was referenced Sep 12, 2026
This was referenced Sep 14, 2026
Open
github-actions Bot
pushed a commit
to sloweyyy/cloud-native-ecommerce-platform
that referenced
this pull request
Sep 14, 2026
Updated [Dapper](https://github.com/DapperLib/Dapper) from 2.1.79 to 2.1.86. <details> <summary>Release notes</summary> _Sourced from [Dapper's releases](https://github.com/DapperLib/Dapper/releases)._ ## 2.1.86 ## What's Changed * Point docs links at dapperlib.dev by @mgravell in DapperLib/Dapper#2222 * Point PackageReleaseNotes at GitHub Releases by @mgravell in DapperLib/Dapper#2223 * Pin the docs site config, and give it a favicon by @mgravell in DapperLib/Dapper#2224 * DynamicParameters.AddParameters(IDbCommand): identity-free self-apply by @mgravell in DapperLib/Dapper#2225 * Re-enable DateOnly/TimeOnly support, fixing the defects that got it disabled by @mgravell in DapperLib/Dapper#2228 * Publish to nuget.org via Trusted Publishing (OIDC), and retire MyGet/AppVeyor by @mgravell in DapperLib/Dapper#2230 **Full Changelog**: DapperLib/Dapper@2.1.79...2.1.86 Commits viewable in [compare view](DapperLib/Dapper@2.1.79...2.1.86). </details> Updated [Microsoft.Extensions.Configuration.Abstractions](https://github.com/dotnet/dotnet) from 10.0.11 to 10.0.12. <details> <summary>Release notes</summary> _Sourced from [Microsoft.Extensions.Configuration.Abstractions's releases](https://github.com/dotnet/dotnet/releases)._ No release notes found for this version range. Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits). </details> Updated [Microsoft.Extensions.Configuration.Binder](https://github.com/dotnet/dotnet) from 10.0.11 to 10.0.12. <details> <summary>Release notes</summary> _Sourced from [Microsoft.Extensions.Configuration.Binder's releases](https://github.com/dotnet/dotnet/releases)._ No release notes found for this version range. Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits). </details> Updated [Microsoft.Extensions.DependencyInjection.Abstractions](https://github.com/dotnet/dotnet) from 10.0.11 to 10.0.12. <details> <summary>Release notes</summary> _Sourced from [Microsoft.Extensions.DependencyInjection.Abstractions's releases](https://github.com/dotnet/dotnet/releases)._ No release notes found for this version range. Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits). </details> Updated [Microsoft.Extensions.Hosting.Abstractions](https://github.com/dotnet/dotnet) from 10.0.11 to 10.0.12. <details> <summary>Release notes</summary> _Sourced from [Microsoft.Extensions.Hosting.Abstractions's releases](https://github.com/dotnet/dotnet/releases)._ No release notes found for this version range. Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits). </details> Updated [Microsoft.Extensions.Logging.Abstractions](https://github.com/dotnet/dotnet) from 10.0.11 to 10.0.12. <details> <summary>Release notes</summary> _Sourced from [Microsoft.Extensions.Logging.Abstractions's releases](https://github.com/dotnet/dotnet/releases)._ No release notes found for this version range. Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits). </details> Updated [MongoDB.Driver](https://github.com/mongodb/mongo-csharp-driver) from 3.11.1 to 3.11.2. <details> <summary>Release notes</summary> _Sourced from [MongoDB.Driver's releases](https://github.com/mongodb/mongo-csharp-driver/releases)._ ## 3.11.2 > [!IMPORTANT] > This is a security patch release. It addresses two CVEs reported against the driver, along with a small number of related fixes. There are no public API changes and no application code changes are required to upgrade. Note that the shape of some queries generated by the LINQ provider and by GridFS has changed — see the individual tickets below. This is a patch release that contains fixes and stability improvements: - [CSHARP-6177](https://jira.mongodb.org/browse/CSHARP-6177) / [CVE-2026-88026](https://www.cve.org/CVERecord?id=CVE-2026-88026): Query filter regex injection via unescaped backslash and bracket in LINQ character-set translation - [CSHARP-6190](https://jira.mongodb.org/browse/CSHARP-6190) / [CVE-2026-88025](https://www.cve.org/CVERecord?id=CVE-2026-88025): Use exact match for file ID in GridFS delete methods - [CSHARP-6213](https://jira.mongodb.org/browse/CSHARP-6213): Normalize SRV target host names to lower case during SRV polling The full list of issues resolved in this release is available at [CSHARP JIRA project](https://jira.mongodb.org/issues/?jql=project%20%3D%20CSHARP%20AND%20fixVersion%20%3D%203.11.2%20ORDER%20BY%20key%20ASC). Documentation on the .NET driver can be found [here](https://www.mongodb.com/docs/drivers/csharp/v3.11/). Commits viewable in [compare view](mongodb/mongo-csharp-driver@v3.11.1...v3.11.2). </details> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This was referenced Sep 14, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The full bag protocol — per-parameter
DbType/direction/size/precision/scale, templates, literal replacement,RemoveUnused— already lives inAddParameters(command, identity), but the identity requirement makes it uncallable from outside:Identity's constructor is internal, andidentity.Sqlis consumed on the first line. This overload builds the identity from the command's own text and type (which is whatidentity.Sqlis in practice), letting external tooling apply a parameter bag without reimplementing the protocol.The immediate consumer is Dapper.AOT: its generated command factories can now support
DynamicParametersarguments by delegating to the bag itself — which gives exact vanilla behavior for the whole surface (includingGet<T>output reads andIParameterCallbacks) because it is the vanilla implementation. The generator probes for this symbol, so it activates only when the referenced Dapper has it; no coordination needed on release timing.Test covers the bag + literal-replacement composition against a closed connection (no database needed). API registered in
PublicAPI.Unshipped.txt.