openpencil/packages/fig
Danila Poyarkov 69dba7002f
refactor: define OpenPencil plugin data in one typed registry (#878)
* fix: validate parsed JSON at untrusted boundaries with Valibot

Clipboard HTML, library revisions from shared storage, MCP and automation
WebSocket messages, the MCP discovery file, sidecar output and AI/MCP tool
arguments were JSON.parse'd and cast to their expected types, so a
malformed payload reached the document or crashed paste. They now go
through v.pipe(v.string(), v.parseJson(), Schema), which reports bad JSON
and a wrong shape as the same validation failure.

The path_set tool rejects an invalid VectorNetwork and shares its parser
with create_vector. The CLI library catalog validates its files and runs
revisions through the same size, identity and content-hash checks as the
app; reading image bytes as index-keyed records also stops them coming
back empty. Hand-rolled typeof readers for plugin data, document metadata,
caches and preferences become schemas with their behaviour preserved, and
readCacheJSON takes a schema for its payload.

open-pencil/no-unvalidated-json-parse rejects type assertions on
JSON.parse results other than `as unknown` in src and packages/*/src.

* refactor: validate parsed JSON in tests and tooling

Extend open-pencil/no-unvalidated-json-parse beyond source: tests, helpers and repo tooling now parse JSON through Valibot schemas instead of asserting a type. The shared fixture reader returns a validated object; its old array annotation never matched the fixtures.

* refactor: define OpenPencil plugin data in one typed registry

Every plugin-data key OpenPencil writes is now a field of OPEN_PENCIL_PLUGIN_DATA in scene-graph, with the Valibot schema that reads it; readPluginData and withPluginData replace per-key constants, JSON.parse and hand-matched pluginId/key filters across fig, core, and vue. Moving OkHCL onto it fixes picking a colour rewriting the layer's other plugin data as OkHCL entries.
2026-10-04 17:32:18 +00:00
..
docs fix(fig): read, render, and write Figma slots (#850) 2026-10-04 00:45:10 +04:00
scripts feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00
src refactor: define OpenPencil plugin data in one typed registry (#878) 2026-10-04 17:32:18 +00:00
tests refactor: define OpenPencil plugin data in one typed registry (#878) 2026-10-04 17:32:18 +00:00
AGENTS.md feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00
package.json build: update dependencies (#873) 2026-10-04 12:48:24 +00:00
README.md feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00
tsconfig.json fix: explain unsupported browsers instead of a blank window (#745) 2026-09-22 14:40:59 +04:00
tsconfig.test.json feat(fig): scaffold package shell 2026-06-30 10:51:36 +03:00
tsdown.config.ts refactor(fig): own Figma clipboard encoding and conversion 2026-09-11 00:36:03 +03:00

@open-pencil/fig

.fig file-format package for OpenPencil.

The package owns the outer .fig archive boundary and is the staged home for Figma-specific SceneGraph conversion policy. Production SceneGraph read/write remains available through @open-pencil/core/io while conversion modules move behind this package's public API.

Current ownership:

  • Complete .fig archive parsing through parseFigBuffer()
  • .fig archive assembly through writeFigArchive()
  • Canvas payload and image resource handling
  • readFigContainer() / writeFigContainer() helpers for raw fig-kiwi payloads
  • .fig source and archive result types
  • NodeChange-to-SceneGraph property conversion, including styles, plugin metadata, text, paint, vector, and font policy, through @open-pencil/fig/node-change
  • Component-property, symbol-override, derived-symbol-data, and instance synchronization policy through @open-pencil/fig/instance-overrides
  • Effective raw-metadata precedence and invalidation over SceneGraph's format-neutral edited-field tracking
  • SceneGraph-to-NodeChange export conversion with an explicit glyph-outline runtime service
  • Package-local archive, conversion, instance, export, and dist smoke tests

Architecture documentation

Start with the package docs for the source model, instance evaluation, materialization, document sessions, export, and validation contracts.

Planned ownership:

  • Oracle-backed .fig fixtures

Non-goals:

  • Generic Kiwi schema/runtime internals — use @open-pencil/kiwi
  • Format-neutral IO registration, export targeting, CanvasKit thumbnails, or browser workers — use @open-pencil/core/io
  • Editor actions, renderer behavior, Vue/app UI, CLI formatting, or MCP transport

This follows the existing @open-pencil/pen pattern: a format package owns its source model/parser and SceneGraph policy, while core registers it in the shared IO system.

Checks

cd packages/fig
bun run check