You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Goa框架请求负载含额外字段未触发校验错误的问题咨询

问题描述

当前现状

我们的serviceDemo服务采用Goa框架实现,所有端点行为一致,核心代码如下:

var _ = goa.Service("serviceDemo", func() { 
    goa.Method("secondEndpoint", func() {
        goa.Payload(SecondEndpointRequestPayload)
        goa.Result(SecondEndpointResponsePayload)
        goa.HTTP(func() {
            goa.Headers(func() {
                goa.Header("first-header", goa.String)
                goa.Header("second-header", goa.String)
            })
            goa.POST("secondEndpoint")
            goa.Response(func() {
                goa.Code(goa.StatusOK)
                goa.ContentType(HTTPContentTypeApplicationJSONCharsetUTF8)
            })
        })
    })

    goa.Error(ErrorNameUnexpected, UnexpectedErrorResponsePayload)
    goa.Error(ErrorNameInvalidPayload, InvalidPayloadErrorResponsePayload)
    goa.Error(ErrorNameNotFound, NotFoundErrorResponsePayload)
    goa.Error(ErrorNameForbidden, ForbiddenErrorResponsePayload)
    goa.HTTP(func() {
        goa.Path("/v1/serviceDemo")
        goa.Response(ErrorNameUnexpected, func() {
            goa.Code(goa.StatusInternalServerError)
            goa.ContentType(HTTPContentTypeApplicationJSONCharsetUTF8)
        })
        goa.Response(ErrorNameInvalidPayload, func() {
            goa.Code(goa.StatusBadRequest)
            goa.ContentType(HTTPContentTypeApplicationJSONCharsetUTF8)
        })
        goa.Response(ErrorNameNotFound, func() {
            goa.Code(goa.StatusNotFound)
            goa.ContentType(HTTPContentTypeApplicationJSONCharsetUTF8)
        })
        goa.Response(ErrorNameForbidden, func() {
            goa.Code(goa.StatusForbidden)
            goa.ContentType(HTTPContentTypeApplicationJSONCharsetUTF8)
        })
    })
})
...
var SecondEndpointRequestPayload = goa.Type("SecondEndpointRequestPayload", func() {
    goa.TypeName("SecondEndpointRequestPayload")

    goa.Attribute("first-header", goa.String)
    goa.Attribute("second-header", goa.String)

    goa.Attribute("field1", goa.String)

    goa.Required(
        "field1",
    )
})

预期结果

当发送包含额外字段的请求负载(如下示例)时,服务应触发无效负载校验错误:

{
"field1": "value1",
"field2": "value2"
}

实际结果

请求返回200 OK状态码,仅field1字段被传递到服务实现中,额外字段被直接忽略。

备注

已查阅Goa官方文档,未找到明确的配置项说明如何开启禁止额外字段的校验,目前了解到框架默认会忽略未定义的额外字段。


解决方案

要让Goa框架对请求负载中的额外字段进行校验并返回错误,只需在请求负载类型定义中添加goa.Strict()约束即可。修改后的SecondEndpointRequestPayload代码如下:

var SecondEndpointRequestPayload = goa.Type("SecondEndpointRequestPayload", func() {
    goa.TypeName("SecondEndpointRequestPayload")

    goa.Attribute("first-header", goa.String)
    goa.Attribute("second-header", goa.String)

    goa.Attribute("field1", goa.String)

    goa.Required(
        "field1",
    )
    // 开启严格模式,校验并拒绝包含未定义字段的请求
    goa.Strict()
})

添加goa.Strict()后,当请求负载中出现未在类型定义中声明的字段(如示例中的field2)时,框架会自动触发InvalidPayloadErrorResponsePayload错误,返回400 Bad Request状态码,符合预期的校验行为。


内容的提问来源于stack exchange,提问作者Amal Boushaki

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 13:03:27