Skip to content

fix(client): make invalid Date error a PrismaClientValidationError - #29718

Merged
aqrln merged 3 commits into
prisma:mainfrom
arab971:fm/fix-invalid-date-serialization-29696
Jul 22, 2026
Merged

fix(client): make invalid Date error a PrismaClientValidationError#29718
aqrln merged 3 commits into
prisma:mainfrom
arab971:fm/fix-invalid-date-serialization-29696

Conversation

@arab971

@arab971 arab971 commented Jul 12, 2026

Copy link
Copy Markdown
Contributor

What

Added isValidDate validation guard in serializeRawParameters so that
invalid Date objects passed to $queryRaw/$executeRaw throw a clear
PrismaClientValidationError instead of silently binding "null" as a
datetime parameter.

This matches the behavior already implemented in serializeJsonQuery.ts for
the non-raw query builder path.

How

  • packages/client/src/runtime/utils/serializeRawParameters.ts:
    • added isValidDate import from './date'
    • added validation check: throws PrismaClientValidationError with
      message Provided Date object is invalid when an invalid Date is passed
  • packages/client/src/__tests__/serializeRawParameters.test.ts:
    • added clientVersion parameter to match new function signature
    • added test case: invalid date throws covering new Date('not a date')
      and new Date('invalid')

Validation

All 27 tests in serializeRawParameters.test.ts and
deserializeRawParameters.test.ts pass.

Fixes #29696

@CLAassistant

CLAassistant commented Jul 12, 2026

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

@coderabbitai

coderabbitai Bot commented Jul 12, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

serializeRawParameters now requires a client version and propagates it through fast and slow serialization paths. Invalid Date values are detected before JSON conversion and throw PrismaClientValidationError with the client version. Raw-query mapping passes the version through all provider paths, and tests cover invalid dates.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed The code now validates invalid Dates in raw parameter serialization and throws a validation error as requested in #29696.
Out of Scope Changes check ✅ Passed The clientVersion plumbing and test signature updates support the fix and do not appear unrelated to the issue.
Title check ✅ Passed The title clearly and accurately summarizes the main change: invalid Date values now raise PrismaClientValidationError.
Description check ✅ Passed The description is directly related to the changeset and explains the validation fix, implementation, and tests.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
✨ Simplify code
  • Create PR with simplified code

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@packages/client/src/runtime/utils/serializeRawParameters.ts`:
- Around line 6-12: Update the catch block in serializeRawParameters to retry
the 'slow' path only for TypeError instances; re-throw all other errors,
including PrismaClientValidationError, so invalid dates and unrelated failures
are not serialized twice.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: b293c209-66f7-4912-a435-ef41248d41dd

📥 Commits

Reviewing files that changed from the base of the PR and between cda80a4 and f6c12a5.

📒 Files selected for processing (2)
  • packages/client/src/__tests__/serializeRawParameters.test.ts
  • packages/client/src/runtime/utils/serializeRawParameters.ts

Comment thread packages/client/src/runtime/utils/serializeRawParameters.ts

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/client/src/runtime/utils/serializeRawParameters.ts (1)

5-5: 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Pass clientVersion through the raw query mappers.
serializeRawParameters now requires clientVersion, but packages/client/src/runtime/core/raw-query/rawQueryArgsMapper.ts still calls it without that argument, so this will fail type-checking until the call sites are updated.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/client/src/runtime/utils/serializeRawParameters.ts` at line 5,
Update the raw query mapping logic in rawQueryArgsMapper to pass its available
clientVersion value into serializeRawParameters at every call site, preserving
the existing parameter serialization behavior.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@packages/client/src/runtime/utils/serializeRawParameters.ts`:
- Line 5: Update the raw query mapping logic in rawQueryArgsMapper to pass its
available clientVersion value into serializeRawParameters at every call site,
preserving the existing parameter serialization behavior.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 9fa693de-8154-43c3-a79c-3f0e42948ee3

📥 Commits

Reviewing files that changed from the base of the PR and between f6c12a5 and b2efcfb.

📒 Files selected for processing (1)
  • packages/client/src/runtime/utils/serializeRawParameters.ts

@arab971
arab971 force-pushed the fm/fix-invalid-date-serialization-29696 branch from b2efcfb to 78d0cab Compare July 12, 2026 18:18
@arab971

arab971 commented Jul 12, 2026

Copy link
Copy Markdown
Contributor Author

Hey @aqrln, would you mind taking a look at this PR? It's a small fix for invalid Date objects passed to `$queryRaw` / `$executeRaw` — they now throw a clear `PrismaClientValidationError` instead of silently binding `"null"` as a datetime parameter. Fixes #29696.

Also addressed the CodeRabbit feedback to pipe `clientVersion` through the raw query args mapper to ensure the error carries the correct client version.

Thanks!

@arab971
arab971 force-pushed the fm/fix-invalid-date-serialization-29696 branch 2 times, most recently from afafce8 to 440b075 Compare July 17, 2026 20:42
@tensordreams
tensordreams changed the base branch from main to v7 July 21, 2026 12:04
@dosubot dosubot Bot added the lgtm This PR has been approved by a maintainer label Jul 21, 2026
@aqrln aqrln changed the title fix(client): reject invalid Date in $queryRaw instead of serializing null (#29696) fix(client): make invalid Date error a PrismaClientValidationError Jul 21, 2026
@tensordreams
tensordreams changed the base branch from v7 to main July 21, 2026 15:09
@arab971
arab971 force-pushed the fm/fix-invalid-date-serialization-29696 branch from 440b075 to 209b676 Compare July 21, 2026 20:14
arab971 and others added 3 commits July 22, 2026 01:29
…null

An invalid Date (e.g. new Date('not a date')) passed to $queryRaw would
silently become { prisma__type: 'date', prisma__value: null } and bind
the literal string "null" as a datetime. Now it throws a clear validation
error instead, matching the behavior of the non-raw query builder path.

Fixes prisma#29696

Co-Authored-By: Muhammad Arab <arab@arab.com>
@arab971
arab971 force-pushed the fm/fix-invalid-date-serialization-29696 branch from 209b676 to 894e91e Compare July 21, 2026 20:37
@arab971
arab971 requested a review from aqrln July 21, 2026 20:41
@aqrln
aqrln merged commit 19a272c into prisma:main Jul 22, 2026
242 of 243 checks passed
lh0x00 pushed a commit to lh0x00/prisma that referenced this pull request Aug 9, 2026
…risma#29718)

## What

Added `isValidDate` validation guard in `serializeRawParameters` so that
invalid `Date` objects passed to `$queryRaw`/`$executeRaw` throw a clear
`PrismaClientValidationError` instead of silently binding `"null"` as a
datetime parameter.

This matches the behavior already implemented in `serializeJsonQuery.ts`
for
the non-raw query builder path.

## How

- `packages/client/src/runtime/utils/serializeRawParameters.ts`:
  - added `isValidDate` import from `'./date'`
  - added validation check: throws `PrismaClientValidationError` with
message `Provided Date object is invalid` when an invalid `Date` is
passed
- `packages/client/src/__tests__/serializeRawParameters.test.ts`:
  - added `clientVersion` parameter to match new function signature
- added test case: `invalid date throws` covering `new Date('not a
date')`
    and `new Date('invalid')`

## Validation

All 27 tests in `serializeRawParameters.test.ts` and
`deserializeRawParameters.test.ts` pass.

Fixes prisma#29696

---------

Co-authored-by: Muhammad Arab <arab@arab.com>
OIRNOIR pushed a commit to OIRNOIR/YouTube-Helper-Server that referenced this pull request Sep 1, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [@prisma/adapter-pg](https://github.com/prisma/prisma) ([source](https://github.com/prisma/prisma/tree/HEAD/packages/adapter-pg)) | imports | minor | [`7.9.1` -> `7.10.0`](https://renovatebot.com/diffs/npm/@prisma%2fadapter-pg/7.9.1/7.10.0) |
| [@prisma/client](https://www.prisma.io) ([source](https://github.com/prisma/prisma/tree/HEAD/packages/client)) | imports | minor | [`7.9.1` -> `7.10.0`](https://renovatebot.com/diffs/npm/@prisma%2fclient/7.9.1/7.10.0) |

---

### Release Notes

<details>
<summary>prisma/prisma (@&#8203;prisma/adapter-pg)</summary>

### [`v7.10.0`](https://github.com/prisma/orm/releases/tag/7.10.0)

[Compare Source](prisma/orm@7.9.1...7.10.0)

##### Prisma ORM 7.10.0

Prisma ORM 7.10.0 introduces a compatibility package for running Prisma 7 alongside newer Prisma versions, secures Prisma Studio's local server, and includes fixes across Prisma Client and the PostgreSQL, MariaDB, Neon, SQLite, and Prisma Postgres Serverless adapters.

##### Highlights

##### Run Prisma 7 alongside Prisma 8

This release introduces `@prisma/prisma7`, a compatibility package that lets you retain a matching Prisma 7 CLI and configuration while installing Prisma 8 in the same project.

Once 7.10.0 is released, a side-by-side installation can use:

```sh
npm install --save-dev prisma@8 @prisma/prisma7@7.10.0
npm install @prisma/client@7.10.0
```

Use `prisma` for the directly installed Prisma 8 CLI and `prisma7` for Prisma 7:

```sh
npx prisma --version
npx prisma7 --version

npx prisma7 generate
npx prisma7 migrate dev
npx prisma7 db push
```

Prisma 7 now prefers version-specific configuration files, allowing its configuration to coexist with Prisma 8's `prisma.config.*` files:

```ts
// prisma7.config.ts
import { defineConfig } from '@prisma/prisma7/config'

export default defineConfig({
  schema: 'prisma/schema.prisma',
  migrations: {
    path: 'prisma/migrations',
  },
})
```

Without an explicit `--config` option, Prisma 7 searches for:

1. Root-level `prisma7.config.*` files.
2. `.config/prisma7.*` files.
3. Existing `prisma.config.*` files as a backwards-compatible fallback.

The supported extensions are `.js`, `.ts`, `.mjs`, `.cjs`, `.mts`, and `.cts`. An explicit config path always takes precedence:

```sh
npx prisma7 generate --config ./custom/prisma7.config.ts
```

New projects initialized by the Prisma 7 CLI use `prisma7.config.ts`. Existing projects containing only `prisma.config.*` continue to work without migration or additional warnings. If a `prisma7.config.*` file exists but cannot be loaded, Prisma reports the error rather than silently falling back to another configuration.

The `prisma7` identity is carried through CLI help, version output, shell completion, initialization, migration, database, and generation guidance. Stable Prisma concepts such as `schema.prisma`, Prisma Migrate, `@prisma/client`, and `PRISMA_*` environment variables remain unchanged.

Together, the separate executable and configuration namespace make it possible to operate Prisma 7 and Prisma 8 side by side without command or config-file collisions.

[#&#8203;29949](prisma/orm#29949), [#&#8203;29969](prisma/orm#29969), [#&#8203;29994](prisma/orm#29994), [#&#8203;30000](prisma/orm#30000), [#&#8203;30002](prisma/orm#30002), [#&#8203;30020](prisma/orm#30020)

##### Prisma Studio security hardening

Prisma Studio's local HTTP server now:

- Binds explicitly to `127.0.0.1` instead of all network interfaces.
- Rejects browser requests from origins other than the active `localhost` or `127.0.0.1` Studio URL.
- No longer returns wildcard CORS headers.
- Applies the same protections across Node.js, Bun, and Deno.

This prevents network clients or malicious websites from accessing Studio's database endpoints while Studio is running.

[#&#8203;29890](prisma/orm#29890)

##### Prisma Client

- Fixed `P2002` errors from nested writes so `meta.modelName` identifies the model where the unique constraint violation occurred, including models using `@@map` and `@@schema`. [#&#8203;29628](prisma/orm#29628)
- Fixed automatically batched `findUniqueOrThrow()` calls so every missing record rejects with `P2025`; later misses no longer resolve to `undefined`. [#&#8203;29654](prisma/orm#29654)
- Parameter-chunked statements are now executed atomically in a transaction and rolled back if a later chunk fails. [#&#8203;29771](prisma/orm#29771)
- Improved interactive transaction cleanup during `$disconnect()`, including transactions whose driver-level startup is still in progress. [#&#8203;28768](prisma/orm#28768)
- Prevented transaction cleanup failures after a timeout or backend termination from becoming unhandled promise rejections. [#&#8203;29611](prisma/orm#29611)
- Fixed fluent relation queries when relation fields are literally named `select` or `include`. [#&#8203;29683](prisma/orm#29683)
- Fixed handling of `Date` and `Uint8Array` values created in other JavaScript realms, such as iframes, jsdom, and Node.js `vm` contexts. [#&#8203;29177](prisma/orm#29177)
- Invalid `Date` values passed to `$queryRaw` or `$executeRaw` now throw `PrismaClientValidationError` instead of a generic error. [#&#8203;29718](prisma/orm#29718)
- Fixed `moduleFormat` inference for the `prisma-client` generator in TypeScript projects using `module: "node16"` or `"nodenext"`. Generated output now follows the nearest `package.json` `type`, defaulting to CommonJS when absent. [#&#8203;29712](prisma/orm#29712)
- Deserialized `Bytes` values now own standalone `ArrayBuffer`s rather than exposing unrelated contents from Node.js's shared `Buffer` pool. This applies to both regular and raw query results. [#&#8203;29701](prisma/orm#29701)
- Fixed an incorrect logging context in the remote executor, including Accelerate-backed query execution. [#&#8203;28892](prisma/orm#28892)

##### Client extensions and observability

- Result-extension `compute` callbacks now receive the current model name as a typed second argument:

  ```ts
  compute(data, modelName) {
    // ...
  }
  ```

  The model name is also preserved when multiple extensions compose the same computed field. [#&#8203;29782](prisma/orm#29782)

- Improved OpenTelemetry context for remotely executed queries:

  - `$on('query')` callbacks run within the matching `db_query` span.
  - Events from one operation share the same trace.
  - Error events are recorded as span exceptions.
  - Log events continue to be emitted when tracing is disabled or their reported span is unavailable.

  [#&#8203;28892](prisma/orm#28892)

##### Driver adapters

##### MariaDB

- `@prisma/adapter-mariadb` now accepts an existing `mariadb` pool. External pools remain caller-owned unless `disposeExternalPool: true` is supplied. [#&#8203;27992](prisma/orm#27992)
- Fixed pooled connection leaks during commit, rollback, and failed transaction startup. Connections are now returned with `release()` and transaction-specific listeners are removed before reuse. [#&#8203;29612](prisma/orm#29612)
- Added support for bracketed IPv6 addresses in both `mysql://` and `mariadb://` connection strings. [#&#8203;29026](prisma/orm#29026)
- Prevented malformed connection strings from exposing embedded passwords in retained debug output and diagnostic reports. [#&#8203;27992](prisma/orm#27992)

##### PostgreSQL, Neon, and Prisma Postgres Serverless

- PostgreSQL deadlocks using SQLSTATE `40P01` are now reported as `P2034` transaction write conflicts. [#&#8203;29717](prisma/orm#29717)
- PostgreSQL `RESTRICT` violations using SQLSTATE `23001` are now reported as `P2003`, preserving an available field or constraint name. [#&#8203;29554](prisma/orm#29554)
- `@prisma/adapter-pg` now preserves database constraint names when reporting unique constraint violations through `P2002`. [#&#8203;29587](prisma/orm#29587)
- Prisma Postgres Serverless now prefers the named constraint for `P2002`, falling back to parsed field names when no constraint name is available. [#&#8203;29801](prisma/orm#29801)
- Fixed Neon HTTP adapter serialization for typed parameters such as `Bytes` and `DateTime`. [#&#8203;29747](prisma/orm#29747)

##### SQLite

- `@prisma/adapter-better-sqlite3` now converts previously unhandled SQLite result codes into typed database errors instead of exposing raw driver errors.
- The complete `SQLITE_BUSY` family is now mapped to socket timeout errors, with numeric extended result codes preserved where available.

[#&#8203;29794](prisma/orm#29794)

##### CLI and Migrate

- `prisma generate` can now offer to install Prisma's agent skills. The opt-in prompt:

  - Is shown at most once per machine.
  - Is skipped in CI, containers, Git hooks, npm lifecycle scripts, and watch mode.
  - Is skipped when `--no-hints` is used or Prisma skills are already installed.
  - Times out after 30 seconds.
  - Never causes generation to fail if installation is unsuccessful.

  [#&#8203;29690](prisma/orm#29690)

- A globally installed CLI now warns during `prisma generate` when its version differs from the project's local `prisma` or `@prisma/client`, and recommends running the local CLI. The check is best-effort and does not fail generation. [#&#8203;29593](prisma/orm#29593)

- `prisma version` and `prisma version --json` now include the resolved Prisma CLI package path, making global-versus-local installation issues easier to diagnose. [#&#8203;29573](prisma/orm#29573)

- Empty or generator-only schema files now report `Schema must contain a datasource block` from `db pull`, `db push`, and `migrate dev`, rather than reaching the schema engine and potentially producing inconsistent errors. [#&#8203;29657](prisma/orm#29657)

- CLI commands now tolerate corrupt, unreadable, or unwritable command-state files. Invalid state is reinitialized, writes are atomic, and persistence failures fall back to in-memory state. [#&#8203;29609](prisma/orm#29609)

- Studio now recognizes semicolon-delimited `sqlserver://` connection strings before reporting the existing explicit message that SQL Server is not supported by Studio. [#&#8203;29623](prisma/orm#29623)

- The AI-agent safety checkpoint now also covers interactive `prisma db push` confirmations involving data-loss warnings, rather than only invocations using `--accept-data-loss`. [#&#8203;29793](prisma/orm#29793)

##### Performance and reliability

- Optimized query-plan execution by eagerly evaluating plans with one unconditional database operation and synchronously interpreting the remaining pure plan. Cached plans remain immutable. [#&#8203;29004](prisma/orm#29004)
- Prevented call-stack overflows when rendering very large parameter lists or combining chunked results containing hundreds of thousands of rows. [#&#8203;29751](prisma/orm#29751)
- Reduced ordinary query setup overhead by constructing fluent-relation field maps lazily and in linear time. Non-fluent queries no longer build this map. [#&#8203;29752](prisma/orm#29752)

##### Dependencies

- Updated the transitive `fast-uri` dependency to a patched release addressing production audit advisories affecting versions through `3.1.3`. [#&#8203;29758](prisma/orm#29758)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zMC4zIiwidXBkYXRlZEluVmVyIjoiNDQuMzAuMyIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

Reviewed-on: https://git.oirnoir.dev/OIRNOIR/YouTube-Helper-Server/pulls/41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lgtm This PR has been approved by a maintainer

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Invalid Date passed to $queryRaw/$executeRaw is silently serialized as the string "null" instead of throwing

3 participants