noCV
AMETA-107 · Validate and migrate records

Build parameterized metadata filters with an allowlisted operator set

Practice briefTaskExpert

A query endpoint interpolates client-provided JSON paths and operators into SQL.

Focused work estimate
5h + prerequisites
Priority in the scenario
High
Engineering practice
SQL safety · Query compilation

Estimated field mix

  • Security50%
  • Database engineering50%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

A fictional records portal stores every property in one JSON column. Queries disagree about missing values, and malformed records make ordinary filters fail.

Setup prerequisites

  • Create synthetic document metadata with malformed and legacy versions.
  • Use migrations and a local query API.

Preceding work

Complete these dependencies, or supply their agreed outputs before taking this ticket.

Acceptance criteria

  • Allow only documented fields and operators.
  • Bind user values as parameters and tenant scope as a required predicate.
  • Reject unsupported path syntax before query execution.

Implementation constraints

  • Do not expose arbitrary SQL or JSON-path execution to clients.

Verification to include

  • Filter known numeric and enum metadata under tenant scope.
  • Submit malicious path/operator text and verify no query execution or cross-tenant results.

Deliverables

  • Safe filter compiler and injection regressions

Rollout and recovery

Enable only reviewed filter combinations; disable newly added operators independently if checks fail.

Value of the work

For the engineer: Practice relational/JSON boundaries, versioned validation and query semantics.

For the team: Review a data model that stays inspectable while allowing controlled variation.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.