Skip to content

Document sort input validation and recommend Sort::only() - #257

Open
samdark wants to merge 3 commits into
masterfrom
docs/sort-input-validation
Open

samdark wants to merge 3 commits into
masterfrom
docs/sort-input-validation

Conversation

@samdark

@samdark samdark commented Oct 3, 2026

Copy link
Copy Markdown
Member

Sort::any() accepts unconfigured field names, but the sorting guide could imply that its configuration limits the allowed fields. Recommend Sort::only() by default, show its use with user input, and explain that applications must validate untrusted field names when using Sort::any() to avoid SQL injection with database-backed readers.

Update the English and Portuguese guides, API comments, and changelog.

Q A
Is bugfix? ❌
New feature? ❌
Breaks BC? ❌

Checked PHP syntax and git diff --check; all 22 SortTest tests pass (29 assertions).

Copilot AI balanced review requested due to automatic review settings October 3, 2026 10:20
@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 940b53c7-7920-4e7a-8915-598796d43cd7

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The documentation matches sorting behavior, and the paginator simplification preserves existing semantics.

Review effort: Balanced
Findings: None

What changed in this PR

Clarifies safe sorting practices by recommending Sort::only() for user input and explaining validation requirements for Sort::any().

Changes:

  • Updates English and Portuguese guides with safe usage examples.
  • Adds validation warnings to API comments and records the guidance in the changelog.
  • Simplifies paginator initialization without changing behavior.
File Description
src/​Reader/​Sort.php Adds input-validation guidance to API comments.
src/​Paginator/​KeysetPaginator.php Uses null-coalescing assignment for initialization.
README.md Recommends safe sorting defaults and explains risks.
docs/​guide/​pt-BR/​README.md Adds equivalent Portuguese guidance.
CHANGELOG.md Records the documentation update.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants