Skip to content

Inline escaped literals for Gremlin @graphQuery arguments - #186

Merged
GumpacG merged 1 commit into
mainfrom
gremlin-args
Sep 21, 2026
Merged

GumpacG merged 1 commit into
mainfrom
gremlin-args

Conversation

@GumpacG

@GumpacG GumpacG commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

Gremlin @graphQuery statements with arguments have returned HTTP 400 since v2.1.0. #175 switched argument substitution to Neptune query parameters, which works for openCypher but not Gremlin: Neptune's Gremlin endpoint has no bindings and rejects the query with Bindings in Gremlin are not supported.

This inlines the value as an escaped literal for Gremlin only, preserving #175's injection protection. openCypher keeps parameterized queries unchanged.

strings and enums are escaped and quoted, numbers and booleans emitted unquoted. A quoted placeholder always yields a quoted literal, which matters for ID arguments the graphQL parser reads as numbers substitution is a single pass, so a value containing $name cannot be read as another placeholder and prefixed argument names cannot collide. $ itself is not escaped.

Testing:
The fix was run against Neptune DB 1.4.7.0 and Neptune Analytics.

@GumpacG
GumpacG merged commit 2dde0fe into main Sep 21, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants