Skip to content
Discussion options

You must be logged in to vote

Planning is a pure function — GQL + params in, MongoDB command JSON out — so a model's output can be compiled, validated and rejected before anything touches a database.

const gql     = 'Order($condition:@c0,$sort:@s1,$limit:@l) { code, amount }';
const params  = { c0: { amount: { $gte: 100 } }, s1: { amount: -1 }, l: 20 };

const items = await store.query(gql, params);   // an invalid plan throws before execution

Three properties make this safe to put behind a model:

  • Values are never interpolated into the query text. They live in the params object and are referenced by @key, so there is no string-concatenation surface to inject into.
  • Permissions are enforced while planning, not after ex…

Replies: 1 comment

Comment options

coenddt
Sep 14, 2026
Maintainer Author

You must be logged in to vote
0 replies
Answer selected by coenddt
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
1 participant