When fetching related resources, getResourceType() in CurrentContext gets the resource type fixed to the route instead of retrieving it from the related resource.
This results in the "Invalid nested filtering. Invalid entity reference" error from resolveInternal() in the FieldResolver because the included fields are checked against the wrong entity type.
Example:
We have a node of bundle 'article' with a paragraph field 'field_paragraphs'.
The paragraph has a media reference field 'field_media_image'.
We want to get a list of paragraphs with the field_media_image included:
http://url/jsonapi/node/article/UUID/field_paragraphs?include=field_media_image,field_media_image.field_image
The jsonapi module checks if field_media_image is a field of entity type 'node' instead of 'paragraph'.
See Routes.php line 143 for the route we're using:
// Related resource, like /jsonapi/file/photo/123/comments.
$route_related = (new Route(sprintf('%s/{%s}/{related}', $route_base_path, $resource_type->getEntityTypeId()), $defaults))
->setRequirement('_entity_type', $resource_type->getEntityTypeId())
->setRequirement('_bundle', $resource_type->getBundle())
->setRequirement('_permission', 'access content')
->setRequirement('_jsonapi_custom_query_parameter_names', 'TRUE')
->setOption('parameters', $parameters)
->setOption('_auth', $this->authProviderList())
->setMethods(['GET']);
$route_related->addOptions($options);
$collection->add($build_route_name('related'), $route_related);
In this example, CurrentContext is using file for the entity id instead of comments.
Comments
Comment #2
harrrrrrr commentedComment #3
harrrrrrr commentedComment #4
huyby commentedComment #5
e0ipsoKicking off tests.
Comment #6
e0ipso@harrrrrrr, @huyby can any of you write a test that proves that the issue is fixed?
From a quick glance the code looks good!
Comment #7
huyby commentedI'll add tests asap :)
Comment #8
wim leersCamelcase is fine here.
Nit: should not use camelcase.
Comment #9
wim leersCombined with #2925043: Server error when using the jsonapi.entity.to_jsonapi service, I wonder if this isn't a weakness in the current architecture? (i.e.
CurrentContextallows tricky bugs.)Comment #10
wim leersComment #11
huyby commentedUpdated the patch to work with latest release (1.7) and dev. Had no time to add tests though, not very confident on that, if someone has some good documentation on creating test for this module, would be helpful :-)
Comment #12
huyby commentedForgot to patch the CurrentContext class.
Comment #13
gabesulliceWith #2941685: Port parameter based resource config from REST module landed, CurrentContext no longer exists.
Comment #14
rpayanmMoving to Drupal core's issue queue.
I'm working on https://www.drupal.org/project/drupal/issues/3122113
Comment #15
jibran\Drupal\Tests\jsonapi\Kernel\Normalizer\JsonApiDocumentTopLevelNormalizerTest::testNormalizeRelated()is marked incomplete$this->markTestIncomplete('This fails and should be fixed by https://www.drupal.org/project/drupal/issues/2922121');Comment #16
quietone commentedFollow up made #3213752: Remove dead code from JsonApiDocumentTopLevelNormalizerTest