Files
twenty/packages/twenty-server/test/integration/graphql/suites/mutate-by-relation-field.integration-spec.ts
T
Félix Malfait af4765effe feat(twenty-server): one-hop relation filters in GraphQL API (#20527)
## Summary

Adds support for filtering records by fields on a related MANY_TO_ONE
object via the GraphQL API. Backend only — no frontend, no REST, no
view-filter persistence yet.

```graphql
{
  people(filter: { company: { name: { like: "%Airbnb%" } } }) {
    edges { node { id } }
  }
}
```

### Where the work lands

- **Schema** — `relation-field-metadata-gql-type.generator.ts` now emits
`{relationName}: TargetFilterInput` alongside the existing
`{joinColumnName}: UUIDFilter` for MANY_TO_ONE relations. Mirrors the
order-by generator that already does this for sort. Lazy thunks in
`object-metadata-filter-gql-input-type.generator.ts` handle the cycle
between filter inputs.
- **Arg processor** — `FilterArgProcessorService` no longer hard-rejects
accessing a relation by its name. When the value is a nested object on a
MANY_TO_ONE field, it recurses into the target object's metadata so each
leaf still gets validated and coerced. Depth-capped at 1.
- **Query parser** — new `parseRelationSubFilter` branch in
`graphql-query-filter-field.parser.ts`. When triggered: looks up the
target object metadata, calls `ensureRelationJoin` against the outer
query builder, and recurses via a child
`GraphqlQueryFilterConditionParser` scoped to the target.
`and`/`or`/`not` inside the relation filter keep working because the
child dispatches through the same `parseKeyFilter`.
- **Shared join utility** — `ensureRelationJoin.util.ts` is a single
function that inspects `queryBuilder.expressionMap.joinAttributes` for
the alias before adding a `LEFT JOIN`. Rewired the existing inline
`qb.leftJoin` calls in the order parser and group-by service to use it,
so filter-driven joins no longer collide with sort-driven joins on the
same relation.

### Out of scope (explicit)

- ONE_TO_MANY reverse traversal (needs EXISTS subqueries)
- Aggregates (`company.people.count > 5` — needs HAVING)
- View-filter storage (no `relationPath` column on `ViewFilterEntity`)
- REST DSL changes
- Frontend filter-picker UX
- Nesting deeper than one hop (parser and arg-processor both reject)

### Open question for review

Permissions. The order-by-on-relation code path already lets users sort
People by Company.name without a Company read-permission check, and this
PR matches that behavior for filters — felt wrong to add a stricter gate
only on the filter side. If we want object-permission gating on the
relation target, it should be a follow-up that covers both paths
consistently. The only attack surface today is existence inference via
timing, identical to what sort already exposes.

## Test plan

- [x] `tsc --noEmit` — clean for changed files (5 unrelated pre-existing
errors on main untouched)
- [x] `oxlint --type-aware` + `prettier --check` — 0 errors on all 17
changed/new files
- [x] `jest filter-arg-processor.service.spec` — 229 tests pass (the new
optional `flatObjectMetadataMaps` arg is backwards-compatible)
- [x] Integration test (`filter-by-relation-field.integration-spec.ts`,
6 cases) — needs to be verified against a seeded test DB. Could not
exercise the happy path in my isolated worktree; depth-2 rejection
passed there.
- [ ] EXPLAIN ANALYZE on the integration test query to confirm the FK on
`person.companyId` is indexed for both standard and custom MANY_TO_ONE
relations.

### Integration test cases

1. Filter People by `company.name = "Airbnb"` (exact match)
2. Filter People by `company.name like "%irbnb%"`
3. Non-matching filter returns empty
4. Combined with a scalar filter at root via `and`
5. **Combined with `orderBy` on the same relation** — proves the
join-dedupe works (without `ensureRelationJoin`, TypeORM throws
"duplicate alias")
6. Depth-2 nesting (`company.accountOwner.name`) returns
`INVALID_ARGS_FILTER`

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-14 14:45:32 +02:00

342 lines
11 KiB
TypeScript

import { createManyOperationFactory } from 'test/integration/graphql/utils/create-many-operation-factory.util';
import { deleteManyOperationFactory } from 'test/integration/graphql/utils/delete-many-operation-factory.util';
import { destroyManyOperationFactory } from 'test/integration/graphql/utils/destroy-many-operation-factory.util';
import { findManyOperationFactory } from 'test/integration/graphql/utils/find-many-operation-factory.util';
import { makeGraphqlAPIRequest } from 'test/integration/graphql/utils/make-graphql-api-request.util';
import { restoreManyOperationFactory } from 'test/integration/graphql/utils/restore-many-operation-factory.util';
import { updateManyOperationFactory } from 'test/integration/graphql/utils/update-many-operation-factory.util';
// Distinct ID prefix (eeee / ffff) from filter-by-relation-field.integration-
// spec.ts so the two suites can share the workspace database without colliding.
const TEST_COMPANY_IDS = {
AIRBNB: '20202020-eeee-4000-8000-000000000001',
STRIPE: '20202020-eeee-4000-8000-000000000002',
NOTION: '20202020-eeee-4000-8000-000000000003',
};
const TEST_PERSON_IDS = {
AIRBNB_ENGINEER: '20202020-ffff-4000-8000-000000000001',
AIRBNB_DESIGNER: '20202020-ffff-4000-8000-000000000002',
STRIPE_ENGINEER: '20202020-ffff-4000-8000-000000000003',
NOTION_ENGINEER: '20202020-ffff-4000-8000-000000000004',
UNAFFILIATED: '20202020-ffff-4000-8000-000000000005',
};
const ALL_TEST_PERSON_IDS = Object.values(TEST_PERSON_IDS);
// Each of the four many-record mutations must support relation-traversal
// filters: the join survives into the generated UPDATE / DELETE / SoftDelete /
// Restore SQL via an `id IN (subquery)` rewrite.
describe('Mutate by relation field (e2e)', () => {
const resetFixtures = async () => {
const createCompanies = createManyOperationFactory({
objectMetadataSingularName: 'company',
objectMetadataPluralName: 'companies',
gqlFields: 'id name',
data: [
{ id: TEST_COMPANY_IDS.AIRBNB, name: 'AirbnbMutate' },
{ id: TEST_COMPANY_IDS.STRIPE, name: 'StripeMutate' },
{ id: TEST_COMPANY_IDS.NOTION, name: 'NotionMutate' },
],
upsert: true,
});
await makeGraphqlAPIRequest(createCompanies);
const createPeople = createManyOperationFactory({
objectMetadataSingularName: 'person',
objectMetadataPluralName: 'people',
gqlFields: 'id',
data: [
{
id: TEST_PERSON_IDS.AIRBNB_ENGINEER,
companyId: TEST_COMPANY_IDS.AIRBNB,
jobTitle: 'Engineer',
city: 'Original City',
},
{
id: TEST_PERSON_IDS.AIRBNB_DESIGNER,
companyId: TEST_COMPANY_IDS.AIRBNB,
jobTitle: 'Designer',
city: 'Original City',
},
{
id: TEST_PERSON_IDS.STRIPE_ENGINEER,
companyId: TEST_COMPANY_IDS.STRIPE,
jobTitle: 'Engineer',
city: 'Original City',
},
{
id: TEST_PERSON_IDS.NOTION_ENGINEER,
companyId: TEST_COMPANY_IDS.NOTION,
jobTitle: 'Engineer',
city: 'Original City',
},
{
id: TEST_PERSON_IDS.UNAFFILIATED,
companyId: null,
jobTitle: 'Engineer',
city: 'Original City',
},
],
upsert: true,
});
await makeGraphqlAPIRequest(createPeople);
};
beforeEach(async () => {
// Each test mutates state, so wipe + reseed before every one.
await makeGraphqlAPIRequest(
destroyManyOperationFactory({
objectMetadataSingularName: 'person',
objectMetadataPluralName: 'people',
gqlFields: 'id',
filter: { id: { in: ALL_TEST_PERSON_IDS } },
}),
);
await makeGraphqlAPIRequest(
destroyManyOperationFactory({
objectMetadataSingularName: 'company',
objectMetadataPluralName: 'companies',
gqlFields: 'id',
filter: { id: { in: Object.values(TEST_COMPANY_IDS) } },
}),
);
await resetFixtures();
});
it('should updateMany via a relation traversal filter', async () => {
const updateOperation = updateManyOperationFactory({
objectMetadataSingularName: 'person',
objectMetadataPluralName: 'people',
gqlFields: 'id city',
data: { city: 'Updated City' },
filter: {
and: [
{ id: { in: ALL_TEST_PERSON_IDS } },
{ company: { name: { eq: 'AirbnbMutate' } } },
],
},
});
const updateResponse = await makeGraphqlAPIRequest(updateOperation);
expect(updateResponse.body.errors).toBeUndefined();
const updatedPeople = updateResponse.body.data.updatePeople;
expect(updatedPeople).toHaveLength(2);
expect(
updatedPeople.map((person: { id: string }) => person.id).sort(),
).toEqual(
[TEST_PERSON_IDS.AIRBNB_ENGINEER, TEST_PERSON_IDS.AIRBNB_DESIGNER].sort(),
);
const findOperation = findManyOperationFactory({
objectMetadataSingularName: 'person',
objectMetadataPluralName: 'people',
gqlFields: 'id city',
filter: { id: { in: ALL_TEST_PERSON_IDS } },
});
const findResponse = await makeGraphqlAPIRequest(findOperation);
const cityByPersonId = Object.fromEntries(
findResponse.body.data.people.edges.map(
(edge: { node: { id: string; city: string } }) => [
edge.node.id,
edge.node.city,
],
),
);
expect(cityByPersonId[TEST_PERSON_IDS.AIRBNB_ENGINEER]).toEqual(
'Updated City',
);
expect(cityByPersonId[TEST_PERSON_IDS.AIRBNB_DESIGNER]).toEqual(
'Updated City',
);
// Non-Airbnb rows must stay untouched — the JOIN must not widen the
// mutation past the filter.
expect(cityByPersonId[TEST_PERSON_IDS.STRIPE_ENGINEER]).toEqual(
'Original City',
);
expect(cityByPersonId[TEST_PERSON_IDS.NOTION_ENGINEER]).toEqual(
'Original City',
);
expect(cityByPersonId[TEST_PERSON_IDS.UNAFFILIATED]).toEqual(
'Original City',
);
});
it('should deleteMany via a relation traversal filter (soft-delete)', async () => {
const deleteOperation = deleteManyOperationFactory({
objectMetadataSingularName: 'person',
objectMetadataPluralName: 'people',
gqlFields: 'id deletedAt',
filter: {
and: [
{ id: { in: ALL_TEST_PERSON_IDS } },
{ company: { name: { eq: 'NotionMutate' } } },
],
},
});
const deleteResponse = await makeGraphqlAPIRequest(deleteOperation);
expect(deleteResponse.body.errors).toBeUndefined();
const deletedPeople = deleteResponse.body.data.deletePeople;
expect(deletedPeople).toHaveLength(1);
expect(deletedPeople[0].id).toEqual(TEST_PERSON_IDS.NOTION_ENGINEER);
expect(deletedPeople[0].deletedAt).toBeTruthy();
const findOperation = findManyOperationFactory({
objectMetadataSingularName: 'person',
objectMetadataPluralName: 'people',
gqlFields: 'id',
filter: { id: { in: ALL_TEST_PERSON_IDS } },
});
const findResponse = await makeGraphqlAPIRequest(findOperation);
const remainingIds = findResponse.body.data.people.edges.map(
(edge: { node: { id: string } }) => edge.node.id,
);
expect(remainingIds.sort()).toEqual(
[
TEST_PERSON_IDS.AIRBNB_ENGINEER,
TEST_PERSON_IDS.AIRBNB_DESIGNER,
TEST_PERSON_IDS.STRIPE_ENGINEER,
TEST_PERSON_IDS.UNAFFILIATED,
].sort(),
);
});
it('should restoreMany via a relation traversal filter', async () => {
// Soft-delete via a scalar filter so restore is the only step exercising
// the traversal path.
const deleteOperation = deleteManyOperationFactory({
objectMetadataSingularName: 'person',
objectMetadataPluralName: 'people',
gqlFields: 'id',
filter: {
id: {
in: [
TEST_PERSON_IDS.AIRBNB_ENGINEER,
TEST_PERSON_IDS.AIRBNB_DESIGNER,
TEST_PERSON_IDS.STRIPE_ENGINEER,
],
},
},
});
await makeGraphqlAPIRequest(deleteOperation);
const restoreOperation = restoreManyOperationFactory({
objectMetadataSingularName: 'person',
objectMetadataPluralName: 'people',
gqlFields: 'id deletedAt',
filter: {
and: [
{ id: { in: ALL_TEST_PERSON_IDS } },
{ company: { name: { eq: 'AirbnbMutate' } } },
],
},
});
const restoreResponse = await makeGraphqlAPIRequest(restoreOperation);
expect(restoreResponse.body.errors).toBeUndefined();
const restoredPeople = restoreResponse.body.data.restorePeople;
expect(restoredPeople).toHaveLength(2);
expect(
restoredPeople.map((person: { id: string }) => person.id).sort(),
).toEqual(
[TEST_PERSON_IDS.AIRBNB_ENGINEER, TEST_PERSON_IDS.AIRBNB_DESIGNER].sort(),
);
restoredPeople.forEach((person: { deletedAt: string | null }) => {
expect(person.deletedAt).toBeNull();
});
// The Stripe engineer was soft-deleted too but doesn't match the
// company filter — must remain deleted.
const findStripe = findManyOperationFactory({
objectMetadataSingularName: 'person',
objectMetadataPluralName: 'people',
gqlFields: 'id',
filter: { id: { in: [TEST_PERSON_IDS.STRIPE_ENGINEER] } },
});
const findStripeResponse = await makeGraphqlAPIRequest(findStripe);
expect(findStripeResponse.body.data.people.edges).toEqual([]);
});
it('should destroyMany via a relation traversal filter (hard-delete)', async () => {
const destroyOperation = destroyManyOperationFactory({
objectMetadataSingularName: 'person',
objectMetadataPluralName: 'people',
gqlFields: 'id',
filter: {
and: [
{ id: { in: ALL_TEST_PERSON_IDS } },
{ company: { name: { eq: 'StripeMutate' } } },
],
},
});
const destroyResponse = await makeGraphqlAPIRequest(destroyOperation);
expect(destroyResponse.body.errors).toBeUndefined();
const destroyedPeople = destroyResponse.body.data.destroyPeople;
expect(destroyedPeople).toHaveLength(1);
expect(destroyedPeople[0].id).toEqual(TEST_PERSON_IDS.STRIPE_ENGINEER);
// destroy is a hard-delete — the row must be gone even when querying
// with a deletedAt filter.
const findOperation = findManyOperationFactory({
objectMetadataSingularName: 'person',
objectMetadataPluralName: 'people',
gqlFields: 'id',
filter: {
id: { in: [TEST_PERSON_IDS.STRIPE_ENGINEER] },
not: { deletedAt: { is: 'NULL' } },
},
});
const findResponse = await makeGraphqlAPIRequest(findOperation);
expect(findResponse.body.data.people.edges).toEqual([]);
});
it('should keep scalar-only mutations working unchanged', async () => {
// Pins the no-traversal branch of the mutation builder helper: scalar
// filters keep emitting a direct WHERE without the IN-subquery wrap.
const updateOperation = updateManyOperationFactory({
objectMetadataSingularName: 'person',
objectMetadataPluralName: 'people',
gqlFields: 'id city',
data: { city: 'Scalar Updated City' },
filter: { id: { eq: TEST_PERSON_IDS.UNAFFILIATED } },
});
const updateResponse = await makeGraphqlAPIRequest(updateOperation);
expect(updateResponse.body.errors).toBeUndefined();
expect(updateResponse.body.data.updatePeople).toHaveLength(1);
expect(updateResponse.body.data.updatePeople[0].city).toEqual(
'Scalar Updated City',
);
});
});