When fetching related resources, getResourceType() in CurrentContext gets the resource type fixed to the route instead of retrieving it from the related resource.

This results in the "Invalid nested filtering. Invalid entity reference" error from resolveInternal() in the FieldResolver because the included fields are checked against the wrong entity type.

Example:

We have a node of bundle 'article' with a paragraph field 'field_paragraphs'.

The paragraph has a media reference field 'field_media_image'.

We want to get a list of paragraphs with the field_media_image included:

http://url/jsonapi/node/article/UUID/field_paragraphs?include=field_media_image,field_media_image.field_image

The jsonapi module checks if field_media_image is a field of entity type 'node' instead of 'paragraph'.

See Routes.php line 143 for the route we're using:

      // Related resource, like /jsonapi/file/photo/123/comments.
      $route_related = (new Route(sprintf('%s/{%s}/{related}', $route_base_path, $resource_type->getEntityTypeId()), $defaults))
        ->setRequirement('_entity_type', $resource_type->getEntityTypeId())
        ->setRequirement('_bundle', $resource_type->getBundle())
        ->setRequirement('_permission', 'access content')
        ->setRequirement('_jsonapi_custom_query_parameter_names', 'TRUE')
        ->setOption('parameters', $parameters)
        ->setOption('_auth', $this->authProviderList())
        ->setMethods(['GET']);
      $route_related->addOptions($options);
      $collection->add($build_route_name('related'), $route_related);

In this example, CurrentContext is using file for the entity id instead of comments.

Comments

harrrrrrr created an issue. See original summary.

harrrrrrr’s picture

Issue summary: View changes
harrrrrrr’s picture

Issue summary: View changes
huyby’s picture

e0ipso’s picture

Status: Active » Needs review

Kicking off tests.

e0ipso’s picture

@harrrrrrr, @huyby can any of you write a test that proves that the issue is fixed?

From a quick glance the code looks good!

huyby’s picture

I'll add tests asap :)

wim leers’s picture

Status: Needs review » Needs work
Issue tags: +Needs tests
  1. +++ b/src/Context/CurrentContext.php
    @@ -27,6 +27,13 @@ class CurrentContext {
    +  protected $relatedResourceName;
    

    Camelcase is fine here.

  2. +++ b/src/Normalizer/JsonApiDocumentTopLevelNormalizer.php
    @@ -240,21 +243,23 @@ class JsonApiDocumentTopLevelNormalizer extends NormalizerBase implements Denorm
    +  protected function expandContext(Request $request, ResourceType $resource_type, $relatedResourceName = null) {
    

    Nit: should not use camelcase.

wim leers’s picture

Combined with #2925043: Server error when using the jsonapi.entity.to_jsonapi service, I wonder if this isn't a weakness in the current architecture? (i.e. CurrentContext allows tricky bugs.)

wim leers’s picture

huyby’s picture

Updated the patch to work with latest release (1.7) and dev. Had no time to add tests though, not very confident on that, if someone has some good documentation on creating test for this module, would be helpful :-)

huyby’s picture

Forgot to patch the CurrentContext class.

gabesullice’s picture

Status: Needs work » Closed (outdated)

With #2941685: Port parameter based resource config from REST module landed, CurrentContext no longer exists.

rpayanm’s picture

Project: JSON:API » Drupal core
Version: 8.x-1.x-dev » 8.9.x-dev
Component: Code » jsonapi.module

Moving to Drupal core's issue queue.

I'm working on https://www.drupal.org/project/drupal/issues/3122113

jibran’s picture

\Drupal\Tests\jsonapi\Kernel\Normalizer\JsonApiDocumentTopLevelNormalizerTest::testNormalizeRelated() is marked incomplete
$this->markTestIncomplete('This fails and should be fixed by https://www.drupal.org/project/drupal/issues/2922121');