openpencil/packages/cli/tests/commands/tool.test.ts
Danila Poyarkov e2a3aa3f80
fix: validate parsed JSON at untrusted boundaries with Valibot (#855)
* fix: validate parsed JSON at untrusted boundaries with Valibot

Clipboard HTML, library revisions from shared storage, MCP and automation
WebSocket messages, the MCP discovery file, sidecar output and AI/MCP tool
arguments were JSON.parse'd and cast to their expected types, so a
malformed payload reached the document or crashed paste. They now go
through v.pipe(v.string(), v.parseJson(), Schema), which reports bad JSON
and a wrong shape as the same validation failure.

The path_set tool rejects an invalid VectorNetwork and shares its parser
with create_vector. The CLI library catalog validates its files and runs
revisions through the same size, identity and content-hash checks as the
app; reading image bytes as index-keyed records also stops them coming
back empty. Hand-rolled typeof readers for plugin data, document metadata,
caches and preferences become schemas with their behaviour preserved, and
readCacheJSON takes a schema for its payload.

open-pencil/no-unvalidated-json-parse rejects type assertions on
JSON.parse results other than `as unknown` in src and packages/*/src.

* refactor: validate parsed JSON in tests and tooling

Extend open-pencil/no-unvalidated-json-parse beyond source: tests, helpers and repo tooling now parse JSON through Valibot schemas instead of asserting a type. The shared fixture reader returns a validated object; its old array annotation never matched the fixtures.

* fix: validate clipboard geometry bytes, library images and model catalogs

Clipboard geometry blobs and library image bytes must be bytes at contiguous indexes, so out-of-range or gapped values are rejected instead of silently becoming different geometry or images; serialized library nodes must carry source metadata. The models.dev and OpenRouter responses are validated like their cached copies, and activate-tab rejects a CDP frame it cannot read instead of hanging.

* refactor: extend the JSON validation lint to .json() results

no-unvalidated-json-parse now also rejects type assertions on Response, Bun.file and shell .json() results, the same unchecked parse in another form. MCP server tests read /health through a validated readHealth helper and discovery files through parseDiscoveryInfo; the remaining tooling reads its JSON through schemas.

* test: validate the RPC request body in the CLI app export test

* test: validate CLI JSON output in the tool and app command tests

* test: compare the malformed models.dev fallback with the curated list
2026-10-04 17:01:50 +00:00

85 lines
3.1 KiB
TypeScript

import { describe, expect, setDefaultTimeout, test } from 'bun:test'
import { mkdtemp } from 'node:fs/promises'
import { tmpdir } from 'node:os'
import { join } from 'node:path'
import * as v from 'valibot'
import { CLI_ENTRY, FIXTURES } from '#cli-tests/helpers/paths'
setDefaultTimeout(60_000)
const FIXTURE = join(FIXTURES, 'gold-preview.fig')
function parseJSON<T>(text: string, schema: v.GenericSchema<unknown, T>): T {
return v.parse(v.pipe(v.string(), v.parseJson(), schema), text)
}
async function cli(args: string[]) {
const proc = Bun.spawn([process.execPath, CLI_ENTRY, ...args], { stdout: 'pipe', stderr: 'pipe' })
const [stdout, stderr] = await Promise.all([
new Response(proc.stdout).text(),
new Response(proc.stderr).text()
])
return { stdout: stdout.trim(), stderr: stderr.trim(), exitCode: await proc.exited }
}
describe('tool CLI', () => {
test('lists and describes tools with their effect and argument schema', async () => {
const listed = await cli(['tool', 'list', '--json'])
expect(listed.exitCode).toBe(0)
const tools = parseJSON(
listed.stdout,
v.array(v.looseObject({ name: v.string(), effect: v.string() }))
)
expect(tools).toContainEqual(expect.objectContaining({ name: 'set_fill', effect: 'write' }))
expect(tools).toContainEqual(expect.objectContaining({ name: 'list_pages', effect: 'read' }))
const described = await cli(['tool', 'describe', 'create_page', '--json'])
expect(described.exitCode).toBe(0)
const info = parseJSON(
described.stdout,
v.looseObject({ schema: v.looseObject({ properties: v.record(v.string(), v.unknown()) }) })
)
expect(info.schema.properties).toHaveProperty('name')
})
test('calls a write tool headlessly and saves the result with --output', async () => {
const outPath = join(await mkdtemp(join(tmpdir(), 'open-pencil-tool-')), 'out.fig')
const created = await cli([
'tool',
'call',
'create_page',
FIXTURE,
'--args',
'{"name":"From CLI"}',
'--output',
outPath,
'--json'
])
expect(created.exitCode).toBe(0)
expect(JSON.parse(created.stdout)).toMatchObject({ name: 'From CLI' })
const pages = await cli(['tool', 'call', 'list_pages', outPath, '--json'])
const result = parseJSON(
pages.stdout,
v.looseObject({ pages: v.array(v.looseObject({ name: v.string() })) })
)
expect(result.pages.map((page) => page.name)).toContain('From CLI')
})
test('rejects unknown tools and non-object arguments', async () => {
const unknown = await cli(['tool', 'call', 'not_a_tool', FIXTURE])
expect(unknown.exitCode).toBe(1)
expect(unknown.stderr + unknown.stdout).toContain('Unknown tool "not_a_tool"')
const appWrite = await cli(['tool', 'call', 'create_page', '--output', 'out.fig'])
expect(appWrite.exitCode).toBe(1)
expect(appWrite.stderr).toContain('--write and --output need a document file')
const badArgs = await cli(['tool', 'call', 'list_pages', FIXTURE, '--args', '[1]'])
expect(badArgs.exitCode).toBe(1)
expect(badArgs.stderr + badArgs.stdout).toContain('Tool arguments must be a JSON object')
})
})