Skip to content

[ENG-4061] Recognise more ways handlers read their request - #310

Merged
patchstackdave merged 2 commits into
fix/map-scope-and-routesfrom
fix/map-input-coverage
Sep 29, 2026
Merged

patchstackdave merged 2 commits into
fix/map-scope-and-routesfrom
fix/map-input-coverage

Conversation

@patchstackdave

@patchstackdave patchstackdave commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Refs ENG-4061

Stacked on #308. Review that one first; this diff is only the last commit.

The input map now recognises more of the ways handlers read their request. Each addition names the field in the namespace it arrives in, on both the input inventory and the flow side:

  • Query string through the request URL: new URL(request.url).searchParams.get('q'), the same through a URL binding, a searchParams binding or destructured { searchParams }, request.nextUrl, and a request event's url (SvelteKit, Astro). Other members of the URL are not treated as request fields.
  • Other names for the request: const r = req, and aliases of a namespace (const b = req.body, const q = req.query, const h = request.headers). A field destructured from req.body now proves its flow. An alias of the body is not treated as the request itself.
  • Framework request objects: a request event's request (SvelteKit, Astro), and a route context's params in the second argument (Next.js).
  • Hono: c.req.json(), c.req.query(), c.req.param() and c.req.header(). c.req.query(...) is no longer inventoried as a database call.
  • Next.js Pages Router: the default export of a pages/api/** file, whether declared in place, as an arrow, or exported by name. Its route comes from the file location. Default exports elsewhere under pages/ are not endpoints.
  • Schemas declared outside the handler: Schema.parse(await request.json()) reads the fields of a schema declared in the same module. When the schema is imported from another module, its fields cannot be read, so the endpoint is marked inputsResolved: false.

A read through any of these keeps the reassignment marker of the binding it comes from. Once that binding is assigned again, the read proves reachability (transformed-local) but not an exact value. new URL(...) counts only when URL is the global constructor or globalThis.URL; a local or imported URL does not.

Effect on map output
Maps of apps using these idioms gain inputs, proven flows and, for Pages Router apps, endpoints.

Validation: full suite (3,516 passed, 7 skipped), typecheck, build. New regression tests fail on the base branch, and each rule has its own test.

🤖 Generated with Claude Code

The input map now follows:
- the query string through a URL of the request: new URL(request.url),
  request.nextUrl, a request event's url, and their searchParams;
- another name for the request (const r = req) or one of its namespaces
  (const b = req.body), including fields destructured from them;
- a request event's request and a route context's params;
- Hono's c.req.json(), query(), param() and header(), which are no
  longer inventoried as database calls;
- Next.js Pages Router API routes (the default export of pages/api/**);
- a validator schema declared elsewhere in the module and applied to the
  request. One imported from another module marks the endpoint's inputs
  as unresolved.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderbuds

coderbuds Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Adds support for diverse request reading idioms with extensive input mapping coverage.

🎯 Quality: 84% Excellent · 📦 Size: Large — consider splitting if possible

🛡️ Standards: Not checked — 537 lines changed, over your team's 400-line limit, and nothing checked before it was opened. Coding agents can call the assess-change-fit tool first, while a change this size is still cheap to split.

🤖 Authorship: Agent-written — Claude Code, going by its own attribution. Whether a person read it is unknown; coding agents can call the report-ai-usage tool to say.

📈 This month: Your 163rd PR — above team average · Averaging Good

See how your team is trending →

…obal URL

A read through a URL of the request, its searchParams, a body read or a
Hono accessor now keeps the reassignment marker of the binding it comes
from, so it proves reachability but not an exact value once that binding
has been assigned again.

new URL(...) is only a URL of the request when URL is the global
constructor (or globalThis.URL). A local or imported binding named URL
can return anything, so reads through it are not request fields.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@patchstackdave
patchstackdave added this pull request to stack #316 September 29, 2026 08:02
@patchstackdave

Copy link
Copy Markdown
Contributor Author

/review

@patchstackdave
patchstackdave merged commit 566084b into main Sep 29, 2026
18 checks passed
@patchstackdave
patchstackdave deleted the fix/map-input-coverage branch September 29, 2026 09:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants