Skip to content

fix: validate assignment target in JsonPointer.set() - #80

Merged
stefankoegl merged 3 commits into
stefankoegl:masterfrom
abhi-0203:fix/set-validate-assignment-target
Oct 2, 2026
Merged

stefankoegl merged 3 commits into
stefankoegl:masterfrom
abhi-0203:fix/set-validate-assignment-target

Conversation

@abhi-0203

Copy link
Copy Markdown
Contributor

Summary

JsonPointer.set() raised raw TypeError or IndexError instead of JsonPointerException when the assignment target was invalid — strings or out-of-range list indices. This violates RFC 6901 and causes jsonpatch.apply() to crash on untrusted patch documents.

Fix

Added validation in set():

  1. String guard — str is a Sequence so it passed the part == '-' check but raises TypeError on item assignment. Added explicit isinstance(parent, str) check.
  2. Try/except wrapper — wrapped parent[part] = value in try/except (TypeError, IndexError) to catch any remaining invalid assignment targets and re-raise as JsonPointerException.

Reproduction (before fix)

JsonPointer("/0").set("abc", {"v": 1}, inplace=False)
# TypeError: 'str' object does not support item assignment

JsonPointer("/0").set([], 42, inplace=False)
# IndexError: list assignment index out of range

After fix

JsonPointer("/0").set("abc", {"v": 1}, inplace=False)
# JsonPointerException: Cannot set value in a string

JsonPointer("/0").set([], 42, inplace=False)
# JsonPointerException: Invalid assignment target: list assignment index out of range

All 23 existing tests pass.

Raise JsonPointerException instead of TypeError/IndexError when the
assignment target does not support item assignment.

- str is a Sequence so it bypasses the '-' check but raises TypeError
  on item assignment; catch with explicit isinstance(str) guard.
- Out-of-range list indices raise IndexError; wrap in try/except.

Fixes: stefankoegl#77
Closes: stefankoegl#77

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The /- string case still leaks AttributeError, and the new behavior lacks regression tests.

Review effort: Balanced
Findings: 1 Medium severity · 1 Low severity

Open (2)
What changed in this PR

Improves JsonPointer.set() error normalization for invalid assignment targets.

Changes:

  • Rejects string assignment targets.
  • Converts assignment TypeError/IndexError into JsonPointerException.
File Description
jsonpointer.py Adds assignment-target validation and exception conversion.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread jsonpointer.py Outdated
Comment thread jsonpointer.py
Comment on lines +217 to +220
try:
parent[part] = value
except (TypeError, IndexError) as e:
raise JsonPointerException("Invalid assignment target: %s" % (e,))
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

@angela-tarantula angela-tarantula left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a nice catch. A style improvement would be to use raise ... from e (including more broadly in jsonpointer.py as a whole) as an observability difference between During handling of the above exception, another exception occurred: and The above exception was the direct cause of the following exception:.

Comment thread jsonpointer.py Outdated
Comment on lines +212 to +213
if isinstance(parent, str):
raise JsonPointerException("Cannot set value in a string")

@angela-tarantula angela-tarantula Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Indentation, tests will fail.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Incorrect indentation prevents the module from importing, and the new behavior lacks regression tests.

Review effort: Balanced
Findings: 1 High severity · 1 Low severity

Open (2)
Resolved since last review (1)

Comment thread jsonpointer.py Outdated
…tationError in JsonPointer.set()'

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@stefankoegl
stefankoegl merged commit 8c0bfdd into stefankoegl:master Oct 2, 2026
6 checks passed
@stefankoegl

Copy link
Copy Markdown
Owner

thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants