Skip to content

JS: Add models-as-data for openapi-backend - #22715

Open
anttiviljami wants to merge 2 commits into
github:mainfrom
anttiviljami:js/openapi-backend
Open

anttiviljami wants to merge 2 commits into
github:mainfrom
anttiviljami:js/openapi-backend

Conversation

@anttiviljami

@anttiviljami anttiviljami commented Sep 30, 2026 •

Copy link
Copy Markdown

Added models-as-data support for openapi-backend, a framework-agnostic Node.js library that routes, validates and authenticates requests from an OpenAPI definition.

Background

I maintain openapi-backend as part of openapi-stack.

Upstreaming it means every CodeQL user gets this coverage without extra configuration.

The problem

openapi-backend parses the incoming request itself and passes handlers a context object c, with the request data on c.request (params, query, headers, cookies, requestBody, ...). That object is built inside the library, so no existing source model covers it, and flows like this aren't found:

api.register('getPet', (c) => db.query(`SELECT * FROM pets WHERE id = ${c.request.params.id}`));

The model

c.request becomes a remote source in every handler openapi-backend calls with a context: operation handlers, security handlers, lifecycle handlers and validate predicates. That covers handlers registered:

  • in the constructor (handlers, securityHandlers, validate)
  • with register(name, fn), register({ ... }), registerHandler() and registerSecurityHandler()
  • on the awaited result of init()
  • as TypeScript functions typed (c: Context) => ...

The type names follow the library's real exports (OpenAPIBackend, Handler, Context), so TypeScript annotations match as described in customizing library models for JavaScript.

Checklist

  • Change note in javascript/ql/lib/change-notes/ (minorAnalysis, library pack)
  • Tests: one case per registration style in the existing CWE-089/untyped SQL injection tests, using inline expectations, including a parameterised query that stays unflagged
  • .expected files generated with codeql test run, purely additive
  • No QL changes

Thanks to @sylwia-budzynska from GitHub Security Lab for advising on this contribution!

Mark `context.request` in openapi-backend operation handlers, security
handlers, lifecycle handlers and `validate` predicates as a remote flow
source, covering handlers passed to the constructor, `register()`,
`registerHandler()`, `registerSecurityHandler()`, the awaited result of
`init()`, and TypeScript handlers typed with `Context`.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@anttiviljami
anttiviljami marked this pull request as ready for review September 30, 2026 15:46
Copilot AI balanced review requested due to automatic review settings September 30, 2026 15:46
@anttiviljami
anttiviljami requested a review from a team as a code owner September 30, 2026 15:46

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The new validate and registerHandler model paths lack direct regression coverage.

Review effort: Balanced
Findings: 2 Low severity

Open (2)
What changed in this PR

Adds models-as-data support for treating openapi-backend request contexts as remote input sources.

Changes:

  • Models constructors, initialization, handler registration, and typed contexts.
  • Adds SQL-injection fixtures and generated expectations.
  • Documents the analysis improvement.
File Description
javascript/​ql/​lib/​ext/​openapi-backend.model.yml Defines framework type and source models.
javascript/​ql/​lib/​change-notes/​2026-09-30-openapi-backend.md Adds the library change note.
javascript/​ql/​test/​query-tests/​Security/​CWE-089/​untyped/​openapi-backend.js Tests JavaScript handler flows.
javascript/​ql/​test/​query-tests/​Security/​CWE-089/​untyped/​openapi-backend-typed.ts Tests typed context flow.
javascript/​ql/​test/​query-tests/​Security/​CWE-089/​untyped/​DatabaseAccesses.expected Updates generated database-access results.
javascript/​ql/​test/​query-tests/​Security/​CWE-089/​untyped/​SqlInjection.expected Updates generated SQL-injection results.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread javascript/ql/lib/ext/openapi-backend.model.yml
Comment thread javascript/ql/lib/ext/openapi-backend.model.yml
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants