[ENG-4061] Recognise more ways handlers read their request - #310
Merged
Merged
Conversation
The input map now follows: - the query string through a URL of the request: new URL(request.url), request.nextUrl, a request event's url, and their searchParams; - another name for the request (const r = req) or one of its namespaces (const b = req.body), including fields destructured from them; - a request event's request and a route context's params; - Hono's c.req.json(), query(), param() and header(), which are no longer inventoried as database calls; - Next.js Pages Router API routes (the default export of pages/api/**); - a validator schema declared elsewhere in the module and applied to the request. One imported from another module marks the endpoint's inputs as unresolved. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Adds support for diverse request reading idioms with extensive input mapping coverage. 🎯 Quality: 84% Excellent · 📦 Size: Large — consider splitting if possible 🛡️ Standards: Not checked — 537 lines changed, over your team's 400-line limit, and nothing checked before it was opened. Coding agents can call the 🤖 Authorship: Agent-written — Claude Code, going by its own attribution. Whether a person read it is unknown; coding agents can call the 📈 This month: Your 163rd PR — above team average · Averaging Good |
…obal URL A read through a URL of the request, its searchParams, a body read or a Hono accessor now keeps the reassignment marker of the binding it comes from, so it proves reachability but not an exact value once that binding has been assigned again. new URL(...) is only a URL of the request when URL is the global constructor (or globalThis.URL). A local or imported binding named URL can return anything, so reads through it are not request fields. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
patchstackdave
added this pull request to stack #316
September 29, 2026 08:02
Contributor
Author
|
/review |
mariojgt
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs ENG-4061
Stacked on #308. Review that one first; this diff is only the last commit.
The input map now recognises more of the ways handlers read their request. Each addition names the field in the namespace it arrives in, on both the input inventory and the flow side:
new URL(request.url).searchParams.get('q'), the same through a URL binding, asearchParamsbinding or destructured{ searchParams },request.nextUrl, and a request event'surl(SvelteKit, Astro). Other members of the URL are not treated as request fields.const r = req, and aliases of a namespace (const b = req.body,const q = req.query,const h = request.headers). A field destructured fromreq.bodynow proves its flow. An alias of the body is not treated as the request itself.request(SvelteKit, Astro), and a route context'sparamsin the second argument (Next.js).c.req.json(),c.req.query(),c.req.param()andc.req.header().c.req.query(...)is no longer inventoried as a database call.pages/api/**file, whether declared in place, as an arrow, or exported by name. Its route comes from the file location. Default exports elsewhere underpages/are not endpoints.Schema.parse(await request.json())reads the fields of a schema declared in the same module. When the schema is imported from another module, its fields cannot be read, so the endpoint is markedinputsResolved: false.A read through any of these keeps the reassignment marker of the binding it comes from. Once that binding is assigned again, the read proves reachability (
transformed-local) but not an exact value.new URL(...)counts only whenURLis the global constructor orglobalThis.URL; a local or importedURLdoes not.Effect on map output
Maps of apps using these idioms gain inputs, proven flows and, for Pages Router apps, endpoints.
Validation: full suite (3,516 passed, 7 skipped), typecheck, build. New regression tests fail on the base branch, and each rule has its own test.
🤖 Generated with Claude Code