Harden subprocessor filters per review feedback

Address the review comments on the subprocessors work:

- Reject invalid category/country filter values in the Subprocessors
  resolver with an INVALID error instead of relying solely on transport
  coercion, so a malformed request fails fast and explicitly.
- Use pgx.StrictNamedArgs in the new distinct facet queries so missing
  or extra SQL placeholders stay detectable, matching sibling queries.
- Default a nil ThirdPartyFilter at the service boundary to avoid a nil
  dereference in the coredata list/count paths.
- Expose the category group label as an aria heading for assistive tech.
- Add the missing space in the Select "Selected:" story label.

Signed-off-by: Émile Ré <emile@probo.com>
This commit is contained in:
Émile Ré
2026-07-09 09:31:29 -04:00
parent 52b6ccac55
commit c7c05f0e8d
5 changed files with 16 additions and 3 deletions

View File

@@ -819,6 +819,14 @@ func (r *trustCenterResolver) Subprocessors(ctx context.Context, obj *types.Trus
country = filter.Country
}
if category != nil && !category.IsValid() {
return nil, gqlutils.Invalidf(ctx, "invalid subprocessor category filter: %q", string(*category))
}
if country != nil && !country.IsValid() {
return nil, gqlutils.Invalidf(ctx, "invalid subprocessor country filter: %q", string(*country))
}
showOnTrustCenter := true
thirdPartyFilter := coredata.NewThirdPartyFilter(&showOnTrustCenter, nil, query, category, country)