mirror of
https://github.com/nlohmann/json.git
synced 2026-09-06 16:27:59 +00:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
eca15ca0e5 |
@@ -34,6 +34,8 @@ Strong guarantee: if an exception is thrown, there are no changes in the JSON va
|
||||
("add", "remove", "move")
|
||||
- Throws [`out_of_range.411`](../../home/exceptions.md#jsonexceptionout_of_range411) if an "add" operation's target
|
||||
location has a parent that is neither an object nor an array.
|
||||
- Throws [`out_of_range.413`](../../home/exceptions.md#jsonexceptionout_of_range413) if a "remove" operation's target
|
||||
location has a parent that is neither an object nor an array.
|
||||
- Throws [`other_error.501`](../../home/exceptions.md#jsonexceptionother_error501) if "test" operation was
|
||||
unsuccessful.
|
||||
|
||||
@@ -75,3 +77,5 @@ is thrown. In any case, the original value is not changed: the patch is applied
|
||||
- Added in version 2.0.0.
|
||||
- Added [`out_of_range.411`](../../home/exceptions.md#jsonexceptionout_of_range411) and stopped relying on an internal assertion when an "add" operation's
|
||||
target location has a non-object/non-array parent in version 3.13.0.
|
||||
- Added [`out_of_range.413`](../../home/exceptions.md#jsonexceptionout_of_range413) and stopped silently ignoring a "remove" operation whose target
|
||||
location has a non-object/non-array parent in version 3.13.0.
|
||||
|
||||
@@ -30,6 +30,8 @@ No guarantees, value may be corrupted by an unsuccessful patch operation.
|
||||
("add", "remove", "move")
|
||||
- Throws [`out_of_range.411`](../../home/exceptions.md#jsonexceptionout_of_range411) if an "add" operation's target
|
||||
location has a parent that is neither an object nor an array.
|
||||
- Throws [`out_of_range.413`](../../home/exceptions.md#jsonexceptionout_of_range413) if a "remove" operation's target
|
||||
location has a parent that is neither an object nor an array.
|
||||
- Throws [`other_error.501`](../../home/exceptions.md#jsonexceptionother_error501) if "test" operation was
|
||||
unsuccessful.
|
||||
|
||||
@@ -72,3 +74,5 @@ function throws an exception.
|
||||
- Added in version 3.11.0.
|
||||
- Added [`out_of_range.411`](../../home/exceptions.md#jsonexceptionout_of_range411) and stopped relying on an internal assertion when an "add" operation's
|
||||
target location has a non-object/non-array parent in version 3.13.0.
|
||||
- Added [`out_of_range.413`](../../home/exceptions.md#jsonexceptionout_of_range413) and stopped silently ignoring a "remove" operation whose target
|
||||
location has a non-object/non-array parent in version 3.13.0.
|
||||
|
||||
@@ -933,6 +933,20 @@ BSON stores the length of documents, arrays, strings, and binary values in a sig
|
||||
[`to_bson`](../api/basic_json/to_bson.md) produced documents with negative length prefixes that
|
||||
[`from_bson`](../api/basic_json/from_bson.md) rejected.
|
||||
|
||||
### json.exception.out_of_range.413
|
||||
|
||||
A JSON Patch `remove` operation cannot be applied because the target location's parent is neither an object nor an array. Per [RFC 6902](https://datatracker.ietf.org/doc/html/rfc6902), a `remove` target must reference a member of an existing object or an element of an existing array; a primitive value (string, number, boolean, etc.) or `null` has no members or elements to remove.
|
||||
|
||||
!!! failure "Example message"
|
||||
|
||||
```
|
||||
cannot remove value: the JSON Patch 'remove' target's parent is of type number, but must be an object or array
|
||||
```
|
||||
|
||||
!!! note
|
||||
|
||||
This exception was added in version 3.13.0. Before that, this situation was silently ignored (the `remove` operation had no effect).
|
||||
|
||||
## Further exceptions
|
||||
|
||||
This exception is thrown in case of errors that cannot be classified with the
|
||||
|
||||
@@ -4939,6 +4939,12 @@ class basic_json // NOLINT(cppcoreguidelines-special-member-functions,hicpp-spec
|
||||
// note erase performs range check
|
||||
parent.erase(json_pointer::template array_index<basic_json_t>(last_path));
|
||||
}
|
||||
else
|
||||
{
|
||||
// the parent of a "remove" target must be an object or array
|
||||
// (see #5396)
|
||||
JSON_THROW(out_of_range::create(413, detail::concat("cannot remove value: the JSON Patch 'remove' target's parent is of type ", parent.type_name(), ", but must be an object or array"), &parent));
|
||||
}
|
||||
};
|
||||
|
||||
// type check: top level value must be an array
|
||||
|
||||
@@ -26367,6 +26367,12 @@ class basic_json // NOLINT(cppcoreguidelines-special-member-functions,hicpp-spec
|
||||
// note erase performs range check
|
||||
parent.erase(json_pointer::template array_index<basic_json_t>(last_path));
|
||||
}
|
||||
else
|
||||
{
|
||||
// the parent of a "remove" target must be an object or array
|
||||
// (see #5396)
|
||||
JSON_THROW(out_of_range::create(413, detail::concat("cannot remove value: the JSON Patch 'remove' target's parent is of type ", parent.type_name(), ", but must be an object or array"), &parent));
|
||||
}
|
||||
};
|
||||
|
||||
// type check: top level value must be an array
|
||||
|
||||
+3
-142
@@ -38,54 +38,6 @@ class huge_binary_t : public std::vector<std::uint8_t>
|
||||
using huge_binary_json = nlohmann::basic_json <
|
||||
std::map, std::vector, std::string, bool, std::int64_t, std::uint64_t,
|
||||
double, std::allocator, nlohmann::adl_serializer, huge_binary_t, void >;
|
||||
|
||||
// a string type that can be made to report a size beyond INT32_MAX without
|
||||
// allocating that much memory, so BSON length overflow can be tested for
|
||||
// strings and (embedded) documents as well, following the same idea as
|
||||
// huge_binary_t.
|
||||
//
|
||||
// Unlike huge_binary_t (which is only ever used as the BSON *value* type),
|
||||
// this type doubles as basic_json's StringType and is therefore also used
|
||||
// for *object keys* (e.g. "s" or "nested" below). Only the designated test
|
||||
// value is meant to lie about its size - if every huge_string_t (including
|
||||
// keys) reported a huge size, the running totals computed while walking the
|
||||
// BSON document (see calc_bson_object_size & friends in binary_writer.hpp)
|
||||
// would need more than 32 bits, and on platforms where std::size_t is only
|
||||
// 32 bits wide that arithmetic would silently wrap around, producing wrong
|
||||
// (or even unguarded) lengths. The fake size is therefore opt-in via
|
||||
// as_huge(), and plain strings - in particular object keys - keep reporting
|
||||
// their real, small size.
|
||||
class huge_string_t : public std::string
|
||||
{
|
||||
public:
|
||||
using std::string::string;
|
||||
huge_string_t(const std::string& s) : std::string(s) {} // NOLINT(google-explicit-constructor,hicpp-explicit-conversions)
|
||||
|
||||
// returns a copy of @a s whose size() pretends to be huge
|
||||
static huge_string_t as_huge(const std::string& s)
|
||||
{
|
||||
huge_string_t result(s);
|
||||
result.pretend_huge = true;
|
||||
return result;
|
||||
}
|
||||
|
||||
size_type size() const noexcept
|
||||
{
|
||||
if (pretend_huge)
|
||||
{
|
||||
// one byte more than the BSON length field can represent
|
||||
return static_cast<size_type>((std::numeric_limits<std::int32_t>::max)()) + 1;
|
||||
}
|
||||
return std::string::size();
|
||||
}
|
||||
|
||||
private:
|
||||
bool pretend_huge = false;
|
||||
};
|
||||
|
||||
using huge_string_json = nlohmann::basic_json <
|
||||
std::map, std::vector, huge_string_t, bool, std::int64_t, std::uint64_t,
|
||||
double, std::allocator, nlohmann::adl_serializer, std::vector<std::uint8_t>, void >;
|
||||
} // namespace
|
||||
|
||||
TEST_CASE("BSON")
|
||||
@@ -153,36 +105,10 @@ TEST_CASE("BSON")
|
||||
|
||||
SECTION("lengths exceeding INT32_MAX cannot be serialized to BSON")
|
||||
{
|
||||
// out_of_range.412 is thrown from a single shared helper
|
||||
// (to_bson_length) that guards the BSON length fields of binary
|
||||
// values, strings, and (embedded) documents alike
|
||||
SECTION("binary")
|
||||
{
|
||||
huge_binary_json j;
|
||||
j["b"] = huge_binary_json::binary(huge_binary_t{});
|
||||
huge_binary_json j;
|
||||
j["b"] = huge_binary_json::binary(huge_binary_t{});
|
||||
|
||||
CHECK_THROWS_WITH_AS(huge_binary_json::to_bson(j), "[json.exception.out_of_range.412] BSON length 2147483661 exceeds maximum of 2147483647", huge_binary_json::out_of_range&);
|
||||
}
|
||||
|
||||
SECTION("string")
|
||||
{
|
||||
huge_string_json j;
|
||||
j["s"] = huge_string_t::as_huge("value");
|
||||
|
||||
CHECK_THROWS_WITH_AS(huge_string_json::to_bson(j), "[json.exception.out_of_range.412] BSON length 2147483661 exceeds maximum of 2147483647", huge_string_json::out_of_range&);
|
||||
}
|
||||
|
||||
SECTION("document")
|
||||
{
|
||||
// an oversized string nested one level deep makes the
|
||||
// *embedded* document's own length exceed INT32_MAX as well
|
||||
huge_string_json nested;
|
||||
nested["s"] = huge_string_t::as_huge("value");
|
||||
huge_string_json j;
|
||||
j["nested"] = nested;
|
||||
|
||||
CHECK_THROWS_WITH_AS(huge_string_json::to_bson(j), "[json.exception.out_of_range.412] BSON length 2147483674 exceeds maximum of 2147483647", huge_string_json::out_of_range&);
|
||||
}
|
||||
CHECK_THROWS_WITH_AS(huge_binary_json::to_bson(j), "[json.exception.out_of_range.412] BSON length 2147483661 exceeds maximum of 2147483647", huge_binary_json::out_of_range&);
|
||||
}
|
||||
|
||||
SECTION("string length must be at least 1")
|
||||
@@ -267,23 +193,6 @@ TEST_CASE("BSON")
|
||||
CHECK(json::from_bson(result, true, false) == j);
|
||||
}
|
||||
|
||||
SECTION("non-empty object with bool from a non-0/1 byte (lenient parsing)")
|
||||
{
|
||||
// documented lenient behavior (see gh-5333): any non-zero byte
|
||||
// is accepted as `true`, not just 0x01
|
||||
std::vector<std::uint8_t> const input =
|
||||
{
|
||||
0x0D, 0x00, 0x00, 0x00, // size (little endian)
|
||||
0x08, // entry: boolean
|
||||
'e', 'n', 't', 'r', 'y', '\x00',
|
||||
0x02, // value = 0x02 (neither 0x00 nor 0x01)
|
||||
0x00 // end marker
|
||||
};
|
||||
|
||||
const json expected = { { "entry", true } };
|
||||
CHECK(json::from_bson(input) == expected);
|
||||
}
|
||||
|
||||
SECTION("non-empty object with double")
|
||||
{
|
||||
json const j =
|
||||
@@ -590,29 +499,6 @@ TEST_CASE("BSON")
|
||||
CHECK(json::from_bson(result, true, false) == j);
|
||||
}
|
||||
|
||||
SECTION("array elements with non-conforming keys (lenient parsing)")
|
||||
{
|
||||
// documented lenient behavior (see gh-5333): BSON array element
|
||||
// keys are not checked against the required decimal sequence
|
||||
// "0", "1", "2", ... - elements are taken in encoded order
|
||||
std::vector<std::uint8_t> const input =
|
||||
{
|
||||
0x26, 0x00, 0x00, 0x00, // size (little endian)
|
||||
0x04, 'e', 'n', 't', 'r', 'y', '\x00', // entry: embedded array
|
||||
|
||||
0x1A, 0x00, 0x00, 0x00, // size (little endian)
|
||||
0x10, '5', 0x00, 0x0A, 0x00, 0x00, 0x00, // key "5" (bogus) -> 10
|
||||
0x10, 'x', 0x00, 0x14, 0x00, 0x00, 0x00, // key "x" (non-numeric) -> 20
|
||||
0x10, '1', 0x00, 0x1E, 0x00, 0x00, 0x00, // key "1" (out of order) -> 30
|
||||
0x00, // end marker (embedded array)
|
||||
|
||||
0x00 // end marker
|
||||
};
|
||||
|
||||
const json expected = { { "entry", json::array({10, 20, 30}) } };
|
||||
CHECK(json::from_bson(input) == expected);
|
||||
}
|
||||
|
||||
SECTION("non-empty object with binary member")
|
||||
{
|
||||
const size_t N = 10;
|
||||
@@ -708,31 +594,6 @@ TEST_CASE("BSON")
|
||||
CHECK(json::from_bson(result, true, false) == j);
|
||||
}
|
||||
|
||||
SECTION("binary member with subtype 0x02 (old binary) keeps its inner length prefix (lenient parsing)")
|
||||
{
|
||||
// documented lenient behavior (see gh-5333): the payload for
|
||||
// binary subtype 0x02 ("old binary") is returned as-is,
|
||||
// including its own inner 4-byte length prefix; it is not
|
||||
// stripped or reinterpreted
|
||||
std::vector<std::uint8_t> const input =
|
||||
{
|
||||
0x17, 0x00, 0x00, 0x00, // size (little endian)
|
||||
0x05, 'e', 'n', 't', 'r', 'y', '\x00', // entry: binary
|
||||
|
||||
0x06, 0x00, 0x00, 0x00, // size of binary (little endian)
|
||||
0x02, // "old binary" subtype
|
||||
0x02, 0x00, 0x00, 0x00, // inner length prefix (part of the old-binary payload)
|
||||
0x68, 0x69, // payload ('h', 'i')
|
||||
|
||||
0x00 // end marker
|
||||
};
|
||||
|
||||
// the inner length prefix is part of the (unmodified) payload
|
||||
const std::vector<std::uint8_t> expected_payload = {0x02, 0x00, 0x00, 0x00, 0x68, 0x69};
|
||||
const json expected = { { "entry", json::binary(expected_payload, 0x02) } };
|
||||
CHECK(json::from_bson(input) == expected);
|
||||
}
|
||||
|
||||
SECTION("Some more complex document")
|
||||
{
|
||||
json const j =
|
||||
|
||||
@@ -1389,6 +1389,61 @@ TEST_CASE("JSON patch - add to a primitive parent (regression #4292)")
|
||||
}
|
||||
}
|
||||
|
||||
TEST_CASE("JSON patch - remove with primitive or null parent (regression #5396)")
|
||||
{
|
||||
// Regression test for https://github.com/nlohmann/json/issues/5396
|
||||
//
|
||||
// RFC 6902 (§4.2) requires the target location of a "remove" operation
|
||||
// to exist. When the target's parent resolves to a primitive value or
|
||||
// null, the operation must fail. Previously operation_remove silently
|
||||
// did nothing in this case (neither the "is_object" nor the "is_array"
|
||||
// branch matched, and there was no final "else"), so the patch appeared
|
||||
// to succeed without changing the document. It now throws
|
||||
// out_of_range.413.
|
||||
|
||||
SECTION("parent is a primitive (number)")
|
||||
{
|
||||
json const doc = {{"a", 1}};
|
||||
json const patch = {{{"op", "remove"}, {"path", "/a/b"}}};
|
||||
#if JSON_DIAGNOSTICS
|
||||
CHECK_THROWS_WITH_AS(doc.patch(patch), "[json.exception.out_of_range.413] (/a) cannot remove value: the JSON Patch 'remove' target's parent is of type number, but must be an object or array", json::out_of_range&);
|
||||
#else
|
||||
CHECK_THROWS_WITH_AS(doc.patch(patch), "[json.exception.out_of_range.413] cannot remove value: the JSON Patch 'remove' target's parent is of type number, but must be an object or array", json::out_of_range&);
|
||||
#endif
|
||||
}
|
||||
|
||||
SECTION("parent is a primitive (string)")
|
||||
{
|
||||
json const doc = {{"foo", {{"bar", "a string"}}}};
|
||||
json const patch = {{{"op", "remove"}, {"path", "/foo/bar/baz"}}};
|
||||
#if JSON_DIAGNOSTICS
|
||||
CHECK_THROWS_WITH_AS(doc.patch(patch), "[json.exception.out_of_range.413] (/foo/bar) cannot remove value: the JSON Patch 'remove' target's parent is of type string, but must be an object or array", json::out_of_range&);
|
||||
#else
|
||||
CHECK_THROWS_WITH_AS(doc.patch(patch), "[json.exception.out_of_range.413] cannot remove value: the JSON Patch 'remove' target's parent is of type string, but must be an object or array", json::out_of_range&);
|
||||
#endif
|
||||
}
|
||||
|
||||
SECTION("top-level document is null")
|
||||
{
|
||||
json const doc = nullptr;
|
||||
json const patch = {{{"op", "remove"}, {"path", "/a"}}};
|
||||
CHECK_THROWS_WITH_AS(doc.patch(patch), "[json.exception.out_of_range.413] cannot remove value: the JSON Patch 'remove' target's parent is of type null, but must be an object or array", json::out_of_range&);
|
||||
}
|
||||
|
||||
SECTION("legitimate removes still work")
|
||||
{
|
||||
// object member
|
||||
json const doc1 = {{"a", 1}, {"b", 2}};
|
||||
json const patch1 = {{{"op", "remove"}, {"path", "/a"}}};
|
||||
CHECK(doc1.patch(patch1) == json({{"b", 2}}));
|
||||
|
||||
// array element
|
||||
json const doc2 = R"([1, 2, 3])"_json;
|
||||
json const patch2 = {{{"op", "remove"}, {"path", "/1"}}};
|
||||
CHECK(doc2.patch(patch2) == R"([1, 3])"_json);
|
||||
}
|
||||
}
|
||||
|
||||
TEST_CASE("JSON patch - diff emits array removals in descending index order")
|
||||
{
|
||||
SECTION("array shrunk to empty")
|
||||
|
||||
Reference in New Issue
Block a user