openpencil/packages/fig/tests/node-change
Danila Poyarkov 69dba7002f
refactor: define OpenPencil plugin data in one typed registry (#878)
* fix: validate parsed JSON at untrusted boundaries with Valibot

Clipboard HTML, library revisions from shared storage, MCP and automation
WebSocket messages, the MCP discovery file, sidecar output and AI/MCP tool
arguments were JSON.parse'd and cast to their expected types, so a
malformed payload reached the document or crashed paste. They now go
through v.pipe(v.string(), v.parseJson(), Schema), which reports bad JSON
and a wrong shape as the same validation failure.

The path_set tool rejects an invalid VectorNetwork and shares its parser
with create_vector. The CLI library catalog validates its files and runs
revisions through the same size, identity and content-hash checks as the
app; reading image bytes as index-keyed records also stops them coming
back empty. Hand-rolled typeof readers for plugin data, document metadata,
caches and preferences become schemas with their behaviour preserved, and
readCacheJSON takes a schema for its payload.

open-pencil/no-unvalidated-json-parse rejects type assertions on
JSON.parse results other than `as unknown` in src and packages/*/src.

* refactor: validate parsed JSON in tests and tooling

Extend open-pencil/no-unvalidated-json-parse beyond source: tests, helpers and repo tooling now parse JSON through Valibot schemas instead of asserting a type. The shared fixture reader returns a validated object; its old array annotation never matched the fixtures.

* refactor: define OpenPencil plugin data in one typed registry

Every plugin-data key OpenPencil writes is now a field of OPEN_PENCIL_PLUGIN_DATA in scene-graph, with the Valibot schema that reads it; readPluginData and withPluginData replace per-key constants, JSON.parse and hand-matched pluginId/key filters across fig, core, and vue. Moving OkHCL onto it fixes picking a colour rewriting the layer's other plugin data as OkHCL entries.
2026-10-04 17:32:18 +00:00
..
path fix: convert document colour profiles, keep text edits live, and fix .fig exports (#716) 2026-09-18 00:43:10 +03:00
canvas-guides.test.ts feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00
clone.test.ts feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00
export.test.ts fix(fig)!: clear a colour variable binding when the layer is unbound 2026-10-01 17:06:00 +04:00
font-features.test.ts feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00
index.test.ts fix(core): draw gradient and image strokes as the paint they are (#868) 2026-10-04 13:25:45 +00:00
instance-geometry.test.ts refactor(fig): group prefixed siblings into folders 2026-10-01 16:52:40 +04:00
order-keys.test.ts fix(fig): keep Figma's order keys on instances and untouched siblings (#819) 2026-10-04 10:16:01 +00:00
plugin-data.test.ts refactor: define OpenPencil plugin data in one typed registry (#878) 2026-10-04 17:32:18 +00:00
variable-token.test.ts refactor: define OpenPencil plugin data in one typed registry (#878) 2026-10-04 17:32:18 +00:00