Skip to content

fix: harden search contracts and semantic resource controls - #122

Closed
afoote-mitre wants to merge 5 commits into
devfrom
af/0.4.0-review-01-dependencies
Closed

afoote-mitre wants to merge 5 commits into
devfrom
af/0.4.0-review-01-dependencies

Conversation

@afoote-mitre

@afoote-mitre afoote-mitre commented Aug 5, 2026 •

Copy link
Copy Markdown
Collaborator

Stack

1 of 6 in the 0.4.0 review stack.

  • Base: dev
  • Next: #123

Merge the stack in order. Each later PR is based on the branch immediately before it.

Why These Changes Are Needed

The existing search path trusted incomplete OpenSearch responses, accepted ambiguous structured filters, exposed inconsistent pagination/response behavior, and allowed expensive semantic CPE searches to consume unbounded application work. This first range establishes fail-closed search contracts and the initial resource boundaries before lifecycle and delivery changes are layered on top.

Review Size

Changed lines are additions plus deletions in this PR's adjacent diff. Generated files are package-lock.json and api-docs/openapi.json; tests are *.test.js and files under test/.

Category Changed Lines
Total 2,419
Generated files 267
Tests 1,147
Non-generated, non-test 1,005

Change-to-File Map

Change Why It Is Needed Primary Implementation Files Test / Contract Coverage
Validate OpenSearch response structure Prevent missing hits, totals, or malformed upstream payloads from becoming partial or misleading API success responses. utils/searchProvider.js, controllers/searchController.js, utils/errors.js utils/searchProvider.test.js, controllers/searchController.test.js, utils/errors.test.js
Harden structured filter validation Reject malformed CVSS vectors, invalid dates, ambiguous CPE values, and unsupported sort/filter combinations before DSL construction. controllers/middleware.js, utils/cvss.js, utils/cpe.js, utils/constants.js controllers/middleware.test.js, utils/cvss.test.js, utils/cpe.test.js, routes/cpeName.test.js
Correct pagination and response contracts Keep page metadata, totals, sort behavior, and returned result windows internally consistent. controllers/searchController.js, routes/index.js, utils/searchQueryBuilder.js, routes/swagger.js controllers/searchController.test.js, routes/search.integration.test.js, utils/searchQueryBuilder.test.js, api-docs/openapi.test.js
Bound semantic CPE search work Prevent expensive post-filter searches from consuming unlimited time or duplicating identical in-flight work. utils/searchDeadline.js, utils/searchInFlightRegistry.js, utils/searchPostFilterCache.js, utils/searchPerformance.js, controllers/searchController.js Matching utils/*.test.js suites and controllers/searchController.test.js
Improve generated-diff review Keep generated dependency/OpenAPI churn from obscuring authored code during GitHub review. .gitattributes GitHub Linguist rendering
Align public contracts Ensure README and generated API documentation describe the implemented request, pagination, error, and resource-control behavior. README.md, routes/swagger.js, api-docs/openapi.json api-docs/openapi.test.js

Reviewer Focus

  • Confirm malformed or incomplete upstream responses fail closed.
  • Trace standard pagination separately from semantic CPE post-filter pagination.
  • Review the semantic-search deadline, cache, and in-flight deduplication boundaries.
  • Confirm validation rejects ambiguous inputs without narrowing valid existing searches.

@afoote-mitre
afoote-mitre force-pushed the af/0.4.0-review-01-dependencies branch from 4e89527 to e852140 Compare August 5, 2026 13:17
@afoote-mitre afoote-mitre changed the title chore: establish dependency and delivery policy baseline fix: harden search contracts and semantic resource controls Aug 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant