Conversation
paulpopus
requested review from
AlessioGr,
JarrodMFlesch and
jacobsfletch
as code owners
September 30, 2026 16:31
Contributor
📦 esbuild Bundle Analysis for payloadThis analysis was generated by esbuild-bundle-analyzer. 🤖
Largest pathsThese visualization shows top 20 largest paths in the bundle.Meta file: packages/next/meta_index.json, Out file: esbuild/index.js
Meta file: packages/payload/meta_index.json, Out file: esbuild/index.js
Meta file: packages/payload/meta_shared.json, Out file: esbuild/exports/shared.js
Meta file: packages/richtext-lexical/meta_client.json, Out file: esbuild/exports/client_optimized/index.js
Meta file: packages/ui/meta_client.json, Out file: esbuild/exports/client_optimized/index.js
Meta file: packages/ui/meta_shared.json, Out file: esbuild/exports/shared_optimized/index.js
DetailsNext to the size is how much the size has increased or decreased compared with the base branch of this PR.
|
paulpopus
force-pushed
the
codex/validate-core
branch
from
September 30, 2026 18:26
820d3d4 to
f7e9d1c
Compare
Written with AI
paulpopus
force-pushed
the
codex/validate-core
branch
from
September 30, 2026 19:05
f7e9d1c to
dba35aa
Compare
DanRibbens
requested changes
Oct 2, 2026
DanRibbens
left a comment
Contributor
There was a problem hiding this comment.
Overall I'm aligned with the approach and changes here, just have a few questions:
- It seems like the hooks docs would also need to be updated. Say I have a validate call on a customer user doc, your hooks might call stripe to get a customer stripe id. That logic should be gated by the
operationto say this is required normally, but not for the validate operation. - this may just be scoping for this PR. Did you think about database constraints at all? I can see a gap remaining in this work if you are expecting uniqueness on a field to error and
validatedoesn't query the db to verify this at all. The same concerns applies to compound indexes with unique constraints, which we support.
Written with AI
Written with AI
Written with AI
Written with AI
Written with AI
Member
Author
I've also trimmed the documentation a bit for this new API. |
Written with AI
Written with AI
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Payload can check candidate document data without saving it. Local API, REST API, GraphQL API, and Admin UI callers can run validation and access control before a create, update, or publish operation.
The validation operation does not write documents, versions, jobs, sessions, or uploaded files.
Why
Applications often need to confirm that a document is ready before publication. Previously, callers had to save the document to run the complete validation lifecycle.
How
payload.validate()andpayload.validateGlobal()to the Local API.validateas a request, hook, collection access, global access, and field access operation.API use
Before this change, a caller had to save candidate data to run the complete validation lifecycle.
After this change, a caller can validate the same candidate without a write.
Scope
PR #17557 is the base and final PR into
main. This PR is the implementation layer and targets the #17557 branch. Merge this PR into #17557, then merge #17557 intomain.This PR does not add a built-in Admin UI action for all-locale validation.
Breaking changes
The
Operationtype includesvalidate. Exhaustive request operation checks must handle this value.The
operationargument for collection, global, and fieldbeforeValidateandbeforeChangehooks includesvalidate. Exhaustive hook operation checks must handle this value.Sanitized collection and global access types include a required
validatekey. Configuration sanitization supplies the key automatically.Related work
Written with AI