Skip to content

fix: GraphQL API fails when a class name or mutation alias collides with a built-in name - #10757

Merged
mtrezza merged 1 commit into
parse-community:alphafrom
mtrezza:fix/graphql-builtin-name-collision
Oct 7, 2026
Merged

mtrezza merged 1 commit into
parse-community:alphafrom
mtrezza:fix/graphql-builtin-name-collision

Conversation

@mtrezza

@mtrezza mtrezza commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Pull Request

Issue

GraphQL API fails when a class name or mutation alias collides with a built-in name

Tasks

  • Add tests

Summary by CodeRabbit

  • Bug Fixes
    • GraphQL schema loading now handles name conflicts between generated types or configured query and mutation aliases and built-in GraphQL names. Warnings are shown for applicable conflicts.
  • Tests
    • Added coverage for conflicts involving built-in GraphQL types, Parse-generated types, and built-in query and mutation names.

@parse-github-assistant

Copy link
Copy Markdown

🚀 Thanks for opening this pull request! We appreciate your effort in improving the project. Please let us know once your pull request is ready for review.

Tip

  • Keep pull requests small. Large PRs will be rejected. Break complex features into smaller, incremental PRs.
  • Use Test Driven Development. Write failing tests before implementing functionality. Ensure tests pass.
  • Group code into logical blocks. Add a short comment before each block to explain its purpose.
  • We offer conceptual guidance. Coding is up to you. PRs must be merge-ready for human review.
  • Our review focuses on concept, not quality. PRs with code issues will be rejected. Use an AI agent.
  • Human review time is precious. Avoid review ping-pong. Inspect and test your AI-generated code.

Note

Please respond to review comments from AI agents just like you would to comments from a human reviewer. Let the reviewer resolve their own comments, unless they have reviewed and accepted your commit, or agreed with your explanation for why the feedback was incorrect.

Caution

Pull requests must be written using an AI agent with human supervision. Pull requests written entirely by a human will likely be rejected, because of lower code quality, higher review effort and the higher risk of introducing bugs. Please note that AI review comments on this pull request alone do not satisfy this requirement. Our CI and AI review are safeguards, not development tools. If many issues are flagged, rethink your development approach. Invest more effort in planning and design rather than using review cycles to fix low-quality code.

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: c2cc0ae5-3f0f-4d24-adeb-45d03aa94ffe
📥 Commits

Reviewing files that changed from the base of the PR and between 4ec73c5 and f7674bc.

📒 Files selected for processing (2)
  • spec/ParseGraphQLSchema.spec.js
  • src/GraphQL/ParseGraphQLSchema.js

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The GraphQL schema reserves additional built-in type and mutation names. New tests check schema loading when Parse-generated types or configured query and mutation aliases collide with built-in names.

Changes

GraphQL Name Collision Handling

Layer / File(s) Summary
Built-in type names
src/GraphQL/ParseGraphQLSchema.js, spec/ParseGraphQLSchema.spec.js
The reserved type-name list adds authentication, challenge, schema, configuration, and cloud-config types. Tests check collisions with Parse class names and generated type names.
Built-in mutation names
src/GraphQL/ParseGraphQLSchema.js, spec/ParseGraphQLSchema.spec.js
The reserved mutation-name list adds authentication, password-reset, verification-email, and challenge operations. Tests check collisions with configured query and mutation aliases.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Merge Risk: ⚪ Minimal · up to f7674

No actionable merge-blocking issue is identified; the change is ready for normal checks.

🚥 Pre-merge checks | ✅ 7
✅ Passed checks (7 passed)
Check name Status Explanation
Title check ✅ Passed The title starts with the required fix: prefix and clearly describes the GraphQL collision issue addressed by the changes.
Description check ✅ Passed The description identifies the issue and confirms that tests were added. It omits the template’s Approach section, so it does not explain the implementation.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Security Check ✅ Passed The diff adds only static GraphQL type and field names to reservation lists, plus collision tests. The existing guards use those lists to reject conflicting auto-generated types, queries, and mutation…
Engage In Review Feedback ✅ Passed No review feedback comments were returned, and the current review produced zero actionable findings. There is no feedback in the supplied review metadata that requires discussion, implementation, or r…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Warning

Some tools did not complete. Review the errors below.

🔧 Biome (2.5.13)
src/GraphQL/ParseGraphQLSchema.js

File contains syntax errors that prevent linting: Line 86: return types can only be used in TypeScript files; Line 87: return types can only be used in TypeScript files; Line 88: return types can only be used in TypeScript files; Line 89: return types can only be used in TypeScript files; Line 90: return types can only be used in TypeScript files; Line 91: return types can only be used in TypeScript files; Line 91: expected a semicolon to end the class property, but found none; Line 91: Expected an identifier, a string literal, a number literal, a private field name, or a computed name but instead found '; Line 91: expected , but instead found |; Line 91: expected , but instead found GraphQLSchema; Line 91: expected , but instead found |; Line 91: expected , but instead found DocumentNode; Line 91: expected , but instead found |; Line 91: expected , but instead found GraphQLNamedType; Line 91: expected , but instead found [; Line 91: Expected a class method

... [truncated 2392 characters] ...

und none; Line 477: Expected a semicolon or an implicit semicolon after a statement, but found none; Line 478: Illegal return statement outside of a function; Line 497: expected , but instead found :; Line 498: expected , but instead found parseClasses; Line 498: expected , but instead found :; Line 499: expected , but instead found parseGraphQLConfig; Line 499: expected , but instead found :; Line 500: expected , but instead found functionNamesString; Line 500: expected , but instead found :; Line 501: expected , but instead found }; Line 506: Illegal return statement outside of a function; Line 514: Illegal return statement outside of a function; Line 516: Illegal return statement outside of a function; Line 518: Expected a statement but instead found '}'.


Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.99%. Comparing base (99444cf) to head (f7674bc).
⚠️ Report is 4 commits behind head on alpha.

Additional details and impacted files
@@           Coverage Diff           @@
##            alpha   #10757   +/-   ##
=======================================
  Coverage   93.99%   93.99%           
=======================================
  Files         193      193           
  Lines       17098    17098           
  Branches      259      259           
=======================================
  Hits        16071    16071           
  Misses       1005     1005           
  Partials       22       22           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@mtrezza
mtrezza merged commit 866e82b into parse-community:alpha Oct 7, 2026
42 of 43 checks passed
@mtrezza
mtrezza deleted the fix/graphql-builtin-name-collision branch October 7, 2026 16:14
parseplatformorg pushed a commit that referenced this pull request Oct 7, 2026
## [9.10.4-alpha.1](9.10.3...9.10.4-alpha.1) (2026-10-07)

### Bug Fixes

* GraphQL API fails when a class name or mutation alias collides with a built-in name ([#10757](#10757)) ([866e82b](866e82b))
@parseplatformorg

Copy link
Copy Markdown
Contributor

🎉 This change has been released in version 9.10.4-alpha.1

@parseplatformorg parseplatformorg added the state:released-alpha Released as alpha version label Oct 7, 2026
parseplatformorg pushed a commit that referenced this pull request Oct 9, 2026
## [9.10.4](9.10.3...9.10.4) (2026-10-09)

### Bug Fixes

* Batch and direct access requests fail for object IDs without alphanumeric characters or class names without letters ([#10761](#10761)) ([c8d5ebb](c8d5ebb))
* GraphQL API fails when a class name or mutation alias collides with a built-in name ([#10757](#10757)) ([866e82b](866e82b))
* Object write with a reserved field name can make reads fail on MongoDB ([GHSA-gwrq-q25v-g8mr](GHSA-gwrq-q25v-g8mr)) ([#10763](#10763)) ([d90b841](d90b841))
* Unauthenticated deletion of class schemas removes class-level permissions on MongoDB ([GHSA-qmg9-m772-5rm7](GHSA-qmg9-m772-5rm7)) ([#10767](#10767)) ([2114fca](2114fca))
@parseplatformorg

Copy link
Copy Markdown
Contributor

🎉 This change has been released in version 9.10.4

@parseplatformorg parseplatformorg added the state:released Released as stable version label Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

state:released Released as stable version state:released-alpha Released as alpha version

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants