Skip to content

docs(dev): allowlist user-supplied columns and sort orders in database.rst - #15709

Open
whoalin1 wants to merge 1 commit into
nextcloud:masterfrom
whoalin1:docs-allowlist-columns-sort-database
Open

whoalin1 wants to merge 1 commit into
nextcloud:masterfrom
whoalin1:docs-allowlist-columns-sort-database

Conversation

@whoalin1

@whoalin1 whoalin1 commented Oct 6, 2026 •

Copy link
Copy Markdown

Summary

database.rst showed createNamedParameter() for values but not that column names and sort directions cannot be bound as parameters.

  • Add a short section after the opening query example: allowlist user-supplied columns / sort orders before orderBy() / select().
  • Include a small PHP match example mapping request input onto allowed identifiers.
  • Note the same rule for Repository findBy() orderBy keys.

Closes #15682

Test plan

  • Sphinx build of the developer manual succeeds for the database page
  • New Allowlisting user-supplied columns and sort orders section appears before Transactions
  • Example uses match for column and sort direction allowlists
  • Section mentions orderBy() / select() and Repository findBy()

AI disclosure

This PR was drafted with the help of AI coding assistants (Cursor agents / LLM-based tools), including the description. I am responsible for it and happy to rework anything that doesn't fit.

All commits carry an Assisted-by: Cursor:grok-4.7 trailer.

…e.rst

Assisted-by: Cursor:grok-4.7
Signed-off-by: whoalin1 <[email protected]>
@whoalin1
whoalin1 force-pushed the docs-allowlist-columns-sort-database branch from 8e6ac67 to 167d98a Compare October 9, 2026 14:12

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Developer manual: allowlist user-supplied columns and sort orders in database.rst

1 participant