Conversation
…in where Restore polymorphic join `where` support for a select path that is stored has-many (separate value rows) in one target collection and as a single select column in another, when the targets share identical option values. Each branch is compiled per-collection with its own storage handler and unioned on the stable id/relationTo/sort projection, so the combined caller + access `where` is applied in full to every branch (no dropped or truncated constraints). Shapes that cannot be compiled soundly — text vs number scalars, differing option sets, unsupported operators — remain fail-closed. Adds a security analysis and restoration plan for the remaining categories (localized, array/blocks, relationship/upload/json traversal, geo operators) in polymorphic-join-where-support-plan.md.
Contributor
📦 esbuild Bundle Analysis for payloadThis analysis was generated by esbuild-bundle-analyzer. 🤖
Largest pathsThese visualization shows top 20 largest paths in the bundle.Meta file: packages/next/meta_index.json, Out file: esbuild/index.js
Meta file: packages/payload/meta_index.json, Out file: esbuild/index.js
Meta file: packages/payload/meta_shared.json, Out file: esbuild/exports/shared.js
Meta file: packages/richtext-lexical/meta_client.json, Out file: esbuild/exports/client_optimized/index.js
Meta file: packages/ui/meta_client.json, Out file: esbuild/exports/client_optimized/index.js
Meta file: packages/ui/meta_shared.json, Out file: esbuild/exports/shared_optimized/index.js
DetailsNext to the size is how much the size has increased or decreased compared with the base branch of this PR.
|
This was referenced Sep 21, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Written by AI
Draft. Follow-up to 9339d63 (PYLD-3840). Partially restores one of the polymorphic-join
whereshapes that PR made fail-closed, and documents a secure plan for the rest.What this restores
A
selectfield that is stored has-many (separate value rows) in one polymorphic target collection and as a single select column in another — when the targets share identical option values. This is the common case of the same logical field declaredhasManyin one collection but not another.Each branch is compiled per-collection with its own storage handler (has-many → JSON value-table subquery; single → scalar column) and unioned on the stable
id/relationTo/sortprojection, so the combined caller + accesswhereis applied in full to every branch — nothing dropped or truncated (no PYLD-3840 regression). Tworejects.toThrowmixed-shape tests are flipped to positive filtering assertions that prove the constraint includes the authorized has-many row and excludes the unauthorized scalar row.Shapes that cannot be compiled soundly stay fail-closed: text-vs-number scalars, differing option sets, unsupported operators.
Still deferred (with a plan)
polymorphic-join-where-support-plan.md(included) gives per-category secure implementation plans for the remaining shapes: localized fields,array/blocks,relationship/upload/jsontraversal, and geo operators — each via per-branch correlatedEXISTS/NOT EXISTSsubqueries, with the invariants tied back to the exact PYLD-3840 exploit class they prevent.Verification
packages/drizzle/src/find): 82 passtest/joins/int.spec.ts: 114 pass / 7 skip (sqlite), 121 pass (postgres)Independently re-run and confirmed. Left as a draft for review — not for merge.
3.x backport: #18235