Skip to content

fix: Object write with a reserved field name can make reads fail on MongoDB (GHSA-gwrq-q25v-g8mr) - #10764

Merged
mtrezza merged 2 commits into
parse-community:release-8.x.xfrom
mtrezza:fix/GHSA-gwrq-q25v-g8mr-8.x.x
Oct 8, 2026
Merged

mtrezza merged 2 commits into
parse-community:release-8.x.xfrom
mtrezza:fix/GHSA-gwrq-q25v-g8mr-8.x.x

Conversation

@mtrezza

@mtrezza mtrezza commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

Issue

Object write with a reserved field name can make reads fail on MongoDB (GHSA-gwrq-q25v-g8mr)

Tasks

  • Add tests
  • Add changes to documentation (guides, repository pages, code comments)
  • Add security check
  • Add new Parse Error codes to Parse JS SDK

@parse-github-assistant

Copy link
Copy Markdown

🚀 Thanks for opening this pull request! We appreciate your effort in improving the project. Please let us know once your pull request is ready for review.

Tip

  • Keep pull requests small. Large PRs will be rejected. Break complex features into smaller, incremental PRs.
  • Use Test Driven Development. Write failing tests before implementing functionality. Ensure tests pass.
  • Group code into logical blocks. Add a short comment before each block to explain its purpose.
  • We offer conceptual guidance. Coding is up to you. PRs must be merge-ready for human review.
  • Our review focuses on concept, not quality. PRs with code issues will be rejected. Use an AI agent.
  • Human review time is precious. Avoid review ping-pong. Inspect and test your AI-generated code.

Note

Please respond to review comments from AI agents just like you would to comments from a human reviewer. Let the reviewer resolve their own comments, unless they have reviewed and accepted your commit, or agreed with your explanation for why the feedback was incorrect.

Caution

Pull requests must be written using an AI agent with human supervision. Pull requests written entirely by a human will likely be rejected, because of lower code quality, higher review effort and the higher risk of introducing bugs. Please note that AI review comments on this pull request alone do not satisfy this requirement. Our CI and AI review are safeguards, not development tools. If many issues are flagged, rethink your development approach. Invest more effort in planning and design rather than using review cycles to fix low-quality code.

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: 6a9ba3f8-f8c1-47e3-b24f-0573e77ee5d4
📥 Commits

Reviewing files that changed from the base of the PR and between a8cd6a1 and e5463e3.

📒 Files selected for processing (5)
  • spec/CloudCode.spec.js
  • spec/rest.spec.js
  • src/Adapters/Storage/Mongo/MongoTransform.js
  • src/RestWrite.js
  • src/middlewares.js

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

The change rejects writes to internal fields from ordinary requests, permits master-key and maintenance-key writes, normalizes null context values, and skips unrecognized reserved Mongo keys when converting stored objects.

Changes

Internal Field Handling

Layer / File(s) Summary
Context normalization
src/middlewares.js, spec/CloudCode.spec.js
The middleware removes a body _context value of null. Cloud Code tests expect an empty context for creation and update.
Internal-field write validation
src/RestWrite.js, spec/rest.spec.js, spec/CloudCode.spec.js
RestWrite.execute checks for fields that begin with _. Non-master and non-maintenance requests receive INVALID_KEY_NAME; tests cover rejected writes and privileged deletion of account-lockout fields. The Cloud Code test expects _context writes to fail without invoking save triggers.
Reserved keys in Mongo reads
src/Adapters/Storage/Mongo/MongoTransform.js, spec/rest.spec.js
Mongo conversion logs and skips unrecognized reserved keys. A Mongo-only test checks that reads still return other fields and timestamps.

Priority: ⬆️ High

Estimated code review effort: 3 (Moderate) | ~20 minutes

Merge Risk: ⚪ Minimal · up to e5463

No actionable merge-blocking risk is established; the change is ready for normal checks.


Caution

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

  • Ignore

❌ Failed checks (1 error, 1 warning)

Check name Status Explanation Resolution
Description check ❌ Error No pull request description was provided. The required Issue, Approach, and Tasks information is missing. Add a description that follows the repository template. Include the issue or advisory, describe the implementation approach, and mark the applicable Tasks items.
Docstring Coverage ⚠️ Warning Docstring coverage is 33.33% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 5 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title begins with the required fix: prefix, uses a capitalized first character after the prefix, and identifies the security advisory addressed by the changes.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Security Check ✅ Passed The changed code hardens internal-field handling. RestWrite.execute() now rejects every client-supplied top-level field beginning with _ before triggers or database writes, unless the request uses…
Engage In Review Feedback ✅ Passed The review records show zero actionable findings and no returned CodeRabbit review threads. Therefore, no review feedback required engagement, implementation, or reviewer retraction.
  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 92.69%. Comparing base (2b337d2) to head (e5463e3).
⚠️ Report is 1 commits behind head on release-8.x.x.

Additional details and impacted files
@@                Coverage Diff                @@
##           release-8.x.x   #10764      +/-   ##
=================================================
+ Coverage          92.27%   92.69%   +0.42%     
=================================================
  Files                192      192              
  Lines              16326    16336      +10     
  Branches             238      238              
=================================================
+ Hits               15065    15143      +78     
+ Misses              1236     1172      -64     
+ Partials              25       21       -4     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@mtrezza

mtrezza commented Oct 8, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pre-merge checks failed. Please resolve the failing checks before merging.

@mtrezza mtrezza changed the title fix: GHSA-gwrq-q25v-g8mr fix: Object write with a reserved field name can make reads fail on MongoDB (GHSA-gwrq-q25v-g8mr) Oct 8, 2026
@mtrezza
mtrezza merged commit 9133478 into parse-community:release-8.x.x Oct 8, 2026
45 of 49 checks passed
@mtrezza
mtrezza deleted the fix/GHSA-gwrq-q25v-g8mr-8.x.x branch October 8, 2026 19:01
parseplatformorg pushed a commit that referenced this pull request Oct 8, 2026
## [8.6.100](8.6.99...8.6.100) (2026-10-08)

### Bug Fixes

* Object write with a reserved field name can make reads fail on MongoDB ([GHSA-gwrq-q25v-g8mr](GHSA-gwrq-q25v-g8mr)) ([#10764](#10764)) ([9133478](9133478))
@parseplatformorg

Copy link
Copy Markdown
Contributor

🎉 This change has been released in version 8.6.100

@parseplatformorg parseplatformorg added the state:released-8.x.x Released as LTS version label Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

state:released-8.x.x Released as LTS version

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants