* fix: validate parsed JSON at untrusted boundaries with Valibot Clipboard HTML, library revisions from shared storage, MCP and automation WebSocket messages, the MCP discovery file, sidecar output and AI/MCP tool arguments were JSON.parse'd and cast to their expected types, so a malformed payload reached the document or crashed paste. They now go through v.pipe(v.string(), v.parseJson(), Schema), which reports bad JSON and a wrong shape as the same validation failure. The path_set tool rejects an invalid VectorNetwork and shares its parser with create_vector. The CLI library catalog validates its files and runs revisions through the same size, identity and content-hash checks as the app; reading image bytes as index-keyed records also stops them coming back empty. Hand-rolled typeof readers for plugin data, document metadata, caches and preferences become schemas with their behaviour preserved, and readCacheJSON takes a schema for its payload. open-pencil/no-unvalidated-json-parse rejects type assertions on JSON.parse results other than `as unknown` in src and packages/*/src. * refactor: validate parsed JSON in tests and tooling Extend open-pencil/no-unvalidated-json-parse beyond source: tests, helpers and repo tooling now parse JSON through Valibot schemas instead of asserting a type. The shared fixture reader returns a validated object; its old array annotation never matched the fixtures. * fix: validate clipboard geometry bytes, library images and model catalogs Clipboard geometry blobs and library image bytes must be bytes at contiguous indexes, so out-of-range or gapped values are rejected instead of silently becoming different geometry or images; serialized library nodes must carry source metadata. The models.dev and OpenRouter responses are validated like their cached copies, and activate-tab rejects a CDP frame it cannot read instead of hanging. * refactor: extend the JSON validation lint to .json() results no-unvalidated-json-parse now also rejects type assertions on Response, Bun.file and shell .json() results, the same unchecked parse in another form. MCP server tests read /health through a validated readHealth helper and discovery files through parseDiscoveryInfo; the remaining tooling reads its JSON through schemas. * test: validate the RPC request body in the CLI app export test * test: validate CLI JSON output in the tool and app command tests * test: compare the malformed models.dev fallback with the curated list
76 lines
2.8 KiB
TypeScript
76 lines
2.8 KiB
TypeScript
import { afterEach, describe, expect, test } from 'bun:test'
|
|
|
|
import * as v from 'valibot'
|
|
|
|
function installLocalStorage() {
|
|
const data = new Map<string, string>()
|
|
const storage = {
|
|
get length() {
|
|
return data.size
|
|
},
|
|
getItem: (key: string) => data.get(key) ?? null,
|
|
setItem: (key: string, value: string) => data.set(key, value),
|
|
removeItem: (key: string) => data.delete(key),
|
|
key: (index: number) => [...data.keys()][index] ?? null
|
|
} satisfies Pick<Storage, 'length' | 'getItem' | 'setItem' | 'removeItem' | 'key'>
|
|
|
|
const storageProp = ['local', 'Storage'].join('')
|
|
Object.assign(globalThis, { window: Object.fromEntries([[storageProp, storage]]) })
|
|
return data
|
|
}
|
|
|
|
afterEach(() => {
|
|
Reflect.deleteProperty(globalThis, 'window')
|
|
})
|
|
|
|
describe('app cache', () => {
|
|
test('stores text in the web cache namespace', async () => {
|
|
const storage = installLocalStorage()
|
|
const { readCacheText, writeCacheText } = await import('@/app/cache')
|
|
|
|
await writeCacheText('providers/models', 'cached')
|
|
|
|
expect(storage.get('open-pencil:cache:v1:providers/models')).toBe('cached')
|
|
await expect(readCacheText('providers/models')).resolves.toBe('cached')
|
|
})
|
|
|
|
test('expires JSON values by max age', async () => {
|
|
installLocalStorage()
|
|
const { readCacheJSON, writeCacheJSON } = await import('@/app/cache')
|
|
|
|
await writeCacheJSON('json/key', { ok: true })
|
|
|
|
const schema = v.object({ ok: v.boolean() })
|
|
await expect(readCacheJSON('json/key', schema, 60_000)).resolves.toEqual({ ok: true })
|
|
await expect(readCacheJSON('json/key', schema, -1)).resolves.toBeNull()
|
|
})
|
|
|
|
test('reads malformed or mismatched JSON entries as missing', async () => {
|
|
const storage = installLocalStorage()
|
|
const { readCacheJSON, writeCacheJSON } = await import('@/app/cache')
|
|
const schema = v.object({ ok: v.boolean() })
|
|
|
|
storage.set('open-pencil:cache:v1:json/key', '{not json')
|
|
await expect(readCacheJSON('json/key', schema)).resolves.toBeNull()
|
|
storage.set('open-pencil:cache:v1:json/key', JSON.stringify({ value: { ok: true } }))
|
|
await expect(readCacheJSON('json/key', schema)).resolves.toBeNull()
|
|
await writeCacheJSON('json/key', { ok: 'yes' })
|
|
await expect(readCacheJSON('json/key', schema)).resolves.toBeNull()
|
|
})
|
|
|
|
test('removes a web cache prefix', async () => {
|
|
installLocalStorage()
|
|
const { readCacheText, removeCachePrefix, writeCacheText } = await import('@/app/cache')
|
|
|
|
await writeCacheText('openrouter/models', 'models')
|
|
await writeCacheText('openrouter/other', 'other')
|
|
await writeCacheText('fonts/manifest', 'fonts')
|
|
|
|
await removeCachePrefix('openrouter')
|
|
|
|
await expect(readCacheText('openrouter/models')).resolves.toBeNull()
|
|
await expect(readCacheText('openrouter/other')).resolves.toBeNull()
|
|
await expect(readCacheText('fonts/manifest')).resolves.toBe('fonts')
|
|
})
|
|
})
|