fix: apply sibling keywords when dereferencing $ref - #870
Open
haoku123 wants to merge 1 commit into
Open
Conversation
buildValue resolved $ref by replacing the whole schema, discarding
sibling keywords like required. A property such as
{ $ref: 'Foo', required: ['extra'] } serialized objects missing 'extra'
without raising, letting incomplete data pass silently.
Resolve $ref with siblings by merging the resolved reference with the
sibling keywords (same mergeLocations path used by allOf), keeping the
direct-dereference fast path for schemas containing $ref alone. All
call sites that eagerly resolve $ref now share resolveRefLocation so
properties, array items and nested object properties behave the same.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #866
When a schema contains
$refalongside sibling keywords (e.g.{ $ref: 'Foo', required: ['extra'] }),buildValueresolved the reference and replaced the local schema wholesale, silently discarding the siblings. Objects missing a sibling-required field were serialized as valid.Solution
Added
resolveRefLocation(): schemas containing$refalone keep the direct-dereference fast path; schemas with siblings merge the resolved reference with the sibling keywords using the samemergeLocationspath asallOf(required arrays are unioned by@fastify/merge-json-schemas). All eagerresolveRefcall sites inbuildInnerObjectandbuildArraynow route through it, so properties, array items and tuple items behave consistently.Tests
ref external with sibling required keyword keeps both constraints: missing sibling-required field throws.ref external with sibling required keyword keeps ref constraints: missing ref-required field still throws.Full suite: 493/493 pass, lint clean.