Repository navigation
fix(openapi): give path params precedence in compact input - #2191
Merged
Merged
Conversation
In compact input structure, path params were spread before the query or body, so a colliding key from the client replaced the value the router took from the URL. Middleware that authorized against the path param could then hand the handler a different value than the one it checked. Path params now win on collision. When the body cannot be merged (primitive, array, Blob, ...), only the path params are used, matching the OpenAPI generator. Backports #1947 and #1978 from main.
Contributor
|
This run was cancelled 🛑 The workflow was cancelled before completion. Please check the link below for details. |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
More templates
@orpc/ai-sdk
@orpc/arktype
@orpc/client
@orpc/contract
@orpc/experimental-durable-iterator
@orpc/hey-api
@orpc/interop
@orpc/json-schema
@orpc/nest
@orpc/openapi
@orpc/openapi-client
@orpc/otel
@orpc/experimental-pino
@orpc/experimental-publisher
@orpc/experimental-publisher-durable-object
@orpc/experimental-ratelimit
@orpc/react
@orpc/react-query
@orpc/experimental-react-swr
@orpc/server
@orpc/shared
@orpc/solid-query
@orpc/standard-server
@orpc/standard-server-aws-lambda
@orpc/standard-server-fastify
@orpc/standard-server-fetch
@orpc/standard-server-node
@orpc/standard-server-peer
@orpc/svelte-query
@orpc/tanstack-query
@orpc/trpc
@orpc/valibot
@orpc/vue-colada
@orpc/vue-query
@orpc/zod
commit: |
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ❌ Deployment failed View logs |
orpc | 4c223de | Oct 07 2026, 10:07 AM |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

In
compactinput structure, path params were spread before the query or body, so a colliding key from the client replaced the value the router took from the URL. On 1.15.4,POST /posts/24with body{"id":"99"}reached the handler as{ id: '99' }. Any middleware that authorized against the path param could then hand the handler a different id than the one it checked. Path params now win on collision. This backports #1947 and #1978 frommainto1.x, wherelatestcurrently points.Fixes
input.namecarry the client'sContent-Dispositionfilename on a/{name}route.Compatibility
Round-trips through an oRPC client are unchanged, because the client never sends a key that collides with a path param. The 1.x OpenAPI generator already requires an object input schema containing every path param on compact routes, so bodies that cannot be merged would already have failed validation there.
Docs
The compact input section now says path params take precedence, and that only the path params are used when the body cannot be merged.
Testing
vitest run packages/openapi packages/openapi-client: 416 passed.