openpencil/tests/engine/io/fig/import
Danila Poyarkov e2a3aa3f80
fix: validate parsed JSON at untrusted boundaries with Valibot (#855)
* fix: validate parsed JSON at untrusted boundaries with Valibot

Clipboard HTML, library revisions from shared storage, MCP and automation
WebSocket messages, the MCP discovery file, sidecar output and AI/MCP tool
arguments were JSON.parse'd and cast to their expected types, so a
malformed payload reached the document or crashed paste. They now go
through v.pipe(v.string(), v.parseJson(), Schema), which reports bad JSON
and a wrong shape as the same validation failure.

The path_set tool rejects an invalid VectorNetwork and shares its parser
with create_vector. The CLI library catalog validates its files and runs
revisions through the same size, identity and content-hash checks as the
app; reading image bytes as index-keyed records also stops them coming
back empty. Hand-rolled typeof readers for plugin data, document metadata,
caches and preferences become schemas with their behaviour preserved, and
readCacheJSON takes a schema for its payload.

open-pencil/no-unvalidated-json-parse rejects type assertions on
JSON.parse results other than `as unknown` in src and packages/*/src.

* refactor: validate parsed JSON in tests and tooling

Extend open-pencil/no-unvalidated-json-parse beyond source: tests, helpers and repo tooling now parse JSON through Valibot schemas instead of asserting a type. The shared fixture reader returns a validated object; its old array annotation never matched the fixtures.

* fix: validate clipboard geometry bytes, library images and model catalogs

Clipboard geometry blobs and library image bytes must be bytes at contiguous indexes, so out-of-range or gapped values are rejected instead of silently becoming different geometry or images; serialized library nodes must carry source metadata. The models.dev and OpenRouter responses are validated like their cached copies, and activate-tab rejects a CDP frame it cannot read instead of hanging.

* refactor: extend the JSON validation lint to .json() results

no-unvalidated-json-parse now also rejects type assertions on Response, Bun.file and shell .json() results, the same unchecked parse in another form. MCP server tests read /health through a validated readHealth helper and discovery files through parseDiscoveryInfo; the remaining tooling reads its JSON through schemas.

* test: validate the RPC request body in the CLI app export test

* test: validate CLI JSON output in the tool and app command tests

* test: compare the malformed models.dev fallback with the curated list
2026-10-04 17:01:50 +00:00
..
legacy feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00
basic.test.ts feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00
boolean-operation.test.ts feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00
cancellation.test.ts feat(app): prepare documents atomically per tab (#592) 2026-08-30 12:21:49 +03:00
component-props.test.ts feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00
derived-symbol-data.test.ts feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00
edge-cases.test.ts feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00
field-protection.test.ts feat(scene-graph)!: make a stroke a paint (#864) 2026-10-04 13:38:05 +04:00
font-variations.test.ts refactor(fig): own instance interpretation 2026-07-18 02:06:34 +03:00
group-reclassify.test.ts feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00
instance-overrides.test.ts feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00
instance-regressions.test.ts feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00
lazy-pages.test.ts feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00
mask-oracle.test.ts fix: validate parsed JSON at untrusted boundaries with Valibot (#855) 2026-10-04 17:01:50 +00:00
masks.test.ts refactor(fig): own instance interpretation 2026-07-18 02:06:34 +03:00
paint-schema-fields.test.ts refactor(fig): own instance interpretation 2026-07-18 02:06:34 +03:00
pattern-paint-oracle.test.ts fix: validate parsed JSON at untrusted boundaries with Valibot (#855) 2026-10-04 17:01:50 +00:00
population-delta.test.ts fix(core): show imported page backgrounds and stop fixed text collapsing 2026-10-02 12:10:06 +04:00
property-integrity.test.ts feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00
raw-field-coverage.test.ts fix(fig): preserve explicit text alignment metadata 2026-09-02 22:54:13 +03:00
raw-metadata-oracle.test.ts feat: split SceneGraph and Pen packages 2026-06-30 10:54:32 +03:00
rich-text-oracle.test.ts fix: validate parsed JSON at untrusted boundaries with Valibot (#855) 2026-10-04 17:01:50 +00:00
scaled-instance-strokes.test.ts feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00
schema-coverage.test.ts fix(fig): keep variable metadata, plugin data and default mode on save (#848) 2026-10-04 12:53:04 +04:00
session-ownership.test.ts fix(fig): harden document worker sessions (#594) 2026-08-30 21:40:13 +03:00
strokes.test.ts feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00
style-refs.test.ts feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00
text-path.test.ts feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00
text-sizing.test.ts feat(fig): occurrence-scoped instance interpretation as the single .fig reader 2026-10-01 11:20:27 +04:00