Skip to content

Graph builder does not validate resources or connections: self-loops and duplicate node ids #357

Description

@nicolejms

Steps to reproduce

Two independent cases, both reachable from graph payloads the dashboard does not validate:

  1. A resource that declares a connection to itself. Open that application's graph.
  2. A graph response containing two resources with the same id. Open that application's graph.

Observed behavior

Self-reference. initialNodes in packages/rad-components/src/components/appgraph/AppGraph.tsx emits an edge whose source and target are the same node. React Flow renders this as a self-loop, which is not meaningful in an application graph and overlaps the node it decorates.

Duplicate ids. A node is pushed per entry in graph.resources with no uniqueness check:

nodes.push({
  id: resource.id,
  // ...
});

Two resources with the same id produce two nodes with the same id. React Flow requires node ids to be unique and silently discards or misbehaves on the duplicate, so one of the two resources disappears with no indication. Any edge targeting that id is then ambiguous.

Neither case is validated, and neither produces a warning.

Desired behavior

  • A self-referential connection should be dropped, or rendered in a way that does not imply a dependency cycle on a single node. Silently drawing a loop is the worst of the options.
  • Duplicate resource ids should be de-duplicated deterministically, and the collision should be surfaced rather than resolved by whichever entry React Flow happens to keep.

More generally, initialNodes currently trusts the graph payload completely. A single validation pass over resources and connections before building nodes and edges would cover this, the dangling-edge case in the related issue, and any future shape the API returns.

Workaround

None.

Additional context

Lower severity than the sibling graph issues, since both require unusual payloads — but both are cheap to guard against and neither is currently detectable from the UI.

Pinned by GU-06a and the duplicate-id case in packages/rad-components/src/__test__/graphInvariants.test.ts, with fixtures self-reference.json and duplicate-ids.json under packages/rad-components/src/__fixtures__/graph/, added in nicolejms#1. Both are tagged KNOWN-DEFECT and assert current behavior, so they are expected to fail when this is fixed.

Found while building the graph invariant suite ahead of the graph rearchitecture, tracked in docs/design/2026-09-dashboard-plugin-test-plan.md.

Activity

  1. added
    triagedThis item has been triaged by project maintainers and is in the backlog
    on Sep 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugtriagedThis item has been triaged by project maintainers and is in the backlog

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions