* fix: validate parsed JSON at untrusted boundaries with Valibot Clipboard HTML, library revisions from shared storage, MCP and automation WebSocket messages, the MCP discovery file, sidecar output and AI/MCP tool arguments were JSON.parse'd and cast to their expected types, so a malformed payload reached the document or crashed paste. They now go through v.pipe(v.string(), v.parseJson(), Schema), which reports bad JSON and a wrong shape as the same validation failure. The path_set tool rejects an invalid VectorNetwork and shares its parser with create_vector. The CLI library catalog validates its files and runs revisions through the same size, identity and content-hash checks as the app; reading image bytes as index-keyed records also stops them coming back empty. Hand-rolled typeof readers for plugin data, document metadata, caches and preferences become schemas with their behaviour preserved, and readCacheJSON takes a schema for its payload. open-pencil/no-unvalidated-json-parse rejects type assertions on JSON.parse results other than `as unknown` in src and packages/*/src. * refactor: validate parsed JSON in tests and tooling Extend open-pencil/no-unvalidated-json-parse beyond source: tests, helpers and repo tooling now parse JSON through Valibot schemas instead of asserting a type. The shared fixture reader returns a validated object; its old array annotation never matched the fixtures. * refactor: define OpenPencil plugin data in one typed registry Every plugin-data key OpenPencil writes is now a field of OPEN_PENCIL_PLUGIN_DATA in scene-graph, with the Valibot schema that reads it; readPluginData and withPluginData replace per-key constants, JSON.parse and hand-matched pluginId/key filters across fig, core, and vue. Moving OkHCL onto it fixes picking a colour rewriting the layer's other plugin data as OkHCL entries.
62 lines
2.1 KiB
TypeScript
62 lines
2.1 KiB
TypeScript
import { describe, expect, test } from 'bun:test'
|
|
|
|
import { readModeConditions, readVariableToken } from '#fig/node-change/index'
|
|
|
|
import type { NodeChange } from '@open-pencil/kiwi/fig/codec'
|
|
import { OPEN_PENCIL_PLUGIN_DATA, OPEN_PENCIL_PLUGIN_ID } from '@open-pencil/scene-graph'
|
|
|
|
function record(key: string, value: string): NodeChange {
|
|
return { pluginData: [{ pluginID: OPEN_PENCIL_PLUGIN_ID, key, value }] }
|
|
}
|
|
|
|
describe('token plugin data', () => {
|
|
test('a malformed or wrongly shaped entry reads as no token data', () => {
|
|
expect(
|
|
readVariableToken(record(OPEN_PENCIL_PLUGIN_DATA.token.key, '{not json'), { m: 8 })
|
|
).toEqual({
|
|
unit: undefined,
|
|
expressions: undefined
|
|
})
|
|
expect(
|
|
readVariableToken(record(OPEN_PENCIL_PLUGIN_DATA.token.key, '{"unit":"furlong"}'), { m: 8 })
|
|
).toEqual({
|
|
unit: undefined,
|
|
expressions: undefined
|
|
})
|
|
expect(
|
|
readModeConditions(record(OPEN_PENCIL_PLUGIN_DATA.modeConditions.key, '{"m":42}'))
|
|
).toEqual({})
|
|
expect(
|
|
readModeConditions(record(OPEN_PENCIL_PLUGIN_DATA.modeConditions.key, '{"m":" "}'))
|
|
).toEqual({})
|
|
})
|
|
|
|
test('keep expressions only for modes whose value still matches', () => {
|
|
const nc = record(
|
|
OPEN_PENCIL_PLUGIN_DATA.token.key,
|
|
JSON.stringify({
|
|
unit: 'rem',
|
|
expressions: {
|
|
a: { css: 'clamp(1rem, 4vw, 2rem)', resolved: 16 },
|
|
b: { css: 'clamp(1rem, 4vw, 2rem)', resolved: 16 }
|
|
}
|
|
})
|
|
)
|
|
expect(readVariableToken(nc, { a: 16, b: 20 })).toEqual({
|
|
unit: 'rem',
|
|
expressions: { a: { css: 'clamp(1rem, 4vw, 2rem)', resolved: 16 } }
|
|
})
|
|
})
|
|
|
|
test('match a mode value stored at float32 precision', () => {
|
|
const nc = record(
|
|
OPEN_PENCIL_PLUGIN_DATA.token.key,
|
|
JSON.stringify({ expressions: { a: { css: 'calc(100vw / 3)', resolved: 1234.567 } } })
|
|
)
|
|
// What .fig hands back for 1234.567 after storing it as float32.
|
|
expect(readVariableToken(nc, { a: Math.fround(1234.567) }).expressions).toEqual({
|
|
a: { css: 'calc(100vw / 3)', resolved: 1234.567 }
|
|
})
|
|
})
|
|
})
|