Skip to content

docs(ui): clarify JsVar proposals and hidden Go fields - #534

Merged
linkdata merged 2 commits into
mainfrom
fix/jsvar-partial-hidden-noop
Oct 6, 2026
Merged

linkdata merged 2 commits into
mainfrom
fix/jsvar-partial-hidden-noop

Conversation

@linkdata

@linkdata linkdata commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Document that null proposals for structs zero all Go fields, including unexported and json:"-" fields.
  • Clarify that ClientCheck must validate the complete tentative value, including parent/root changes and fields omitted from JSON.
  • Explain that proposal outcomes can depend on omitted Go fields even when browser JSON is identical; keep secrets outside the bound value.

Scope

Documentation only: the JsVar guide and Go API comments. Runtime code and tests match main.

Verification

  • Focused JsVar tests pass.
  • Generation, formatting, vet, staticcheck, golangci-lint, gosec, and build checked.
  • Final documentation review includes rendered go doc for JsVarCheck and JsVarStore.

A partial JsVarStore whose Go type has unexported or json:"-" fields let a
WebSocket peer learn whether that hidden state was zero. jq skips the
ClientCheck callback for Go-equal values, so a forged `path=null` was a
silent no-op when hidden fields were zero but reached ClientCheck (alert on
deny, publish on allow) when they were not, with identical browser JSON.

Record at store creation whether a plain type has such fields, and for
those stores check and publish unchanged proposals like changed ones. The
check sees the same next value either way, so the outcome depends only on
its decision. This adds no work beyond what a changing proposal already
costs.
@linkdata linkdata changed the title fix(ui): check unchanged JsVar proposals on hidden-field stores docs(ui): clarify JsVar proposals and hidden Go fields Oct 6, 2026
@linkdata
linkdata merged commit 5df89a1 into main Oct 6, 2026
7 checks passed
@linkdata
linkdata deleted the fix/jsvar-partial-hidden-noop branch October 6, 2026 12:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant