Validate view injection in extension $vectorSearch

XMLWordPrintableJSON

    • Type: Task
    • Resolution: Won't Do
    • Priority: Major - P3
    • None
    • Affects Version/s: None
    • Component/s: None
    • Query Integration
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      When search stages ($vectorSearch, $search, $searchMeta) are parsed through the extension code path, the validateViewNotSetByUser check is bypassed, allowing users to inject internal-only view fields into stage specs. This validation currently only exists in the legacy DocumentSourceVectorSearch::createFromBson.

            Assignee:
            Daniel Segel
            Reporter:
            Daniel Segel
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: