Skip to content

Reject non-string JSON values when decoding IDs - #124

Closed
vitalivo wants to merge 1 commit into
rs:masterfrom
vitalivo:fix/json-value-type
Closed

vitalivo wants to merge 1 commit into
rs:masterfrom
vitalivo:fix/json-value-type

Conversation

@vitalivo

Copy link
Copy Markdown
Contributor

json.Unmarshal accepts certain numbers and arrays as IDs because UnmarshalJSON strips the first and last byte without checking for quotes. For example, both 1111111111111111111101 and [11111111111111111110] decode successfully to the ID 11111111111111111110.

Require a JSON string before delegating to UnmarshalText, retaining the existing null handling and short-input guard. Regression tests exercise both valid JSON inputs through encoding/json and verify that rejection leaves the receiver unchanged.

Validation: both cases fail before the fix. go test -race -cover ./... passes (94.3% main-package coverage), go vet ./... passes, and staticcheck passes with tests disabled. Full staticcheck reports the pre-existing unused error assignment in id_test.go:153.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant