openpencil/tests/engine/library/storage-catalog.test.ts
Danila Poyarkov e2a3aa3f80
fix: validate parsed JSON at untrusted boundaries with Valibot (#855)
* fix: validate parsed JSON at untrusted boundaries with Valibot

Clipboard HTML, library revisions from shared storage, MCP and automation
WebSocket messages, the MCP discovery file, sidecar output and AI/MCP tool
arguments were JSON.parse'd and cast to their expected types, so a
malformed payload reached the document or crashed paste. They now go
through v.pipe(v.string(), v.parseJson(), Schema), which reports bad JSON
and a wrong shape as the same validation failure.

The path_set tool rejects an invalid VectorNetwork and shares its parser
with create_vector. The CLI library catalog validates its files and runs
revisions through the same size, identity and content-hash checks as the
app; reading image bytes as index-keyed records also stops them coming
back empty. Hand-rolled typeof readers for plugin data, document metadata,
caches and preferences become schemas with their behaviour preserved, and
readCacheJSON takes a schema for its payload.

open-pencil/no-unvalidated-json-parse rejects type assertions on
JSON.parse results other than `as unknown` in src and packages/*/src.

* refactor: validate parsed JSON in tests and tooling

Extend open-pencil/no-unvalidated-json-parse beyond source: tests, helpers and repo tooling now parse JSON through Valibot schemas instead of asserting a type. The shared fixture reader returns a validated object; its old array annotation never matched the fixtures.

* fix: validate clipboard geometry bytes, library images and model catalogs

Clipboard geometry blobs and library image bytes must be bytes at contiguous indexes, so out-of-range or gapped values are rejected instead of silently becoming different geometry or images; serialized library nodes must carry source metadata. The models.dev and OpenRouter responses are validated like their cached copies, and activate-tab rejects a CDP frame it cannot read instead of hanging.

* refactor: extend the JSON validation lint to .json() results

no-unvalidated-json-parse now also rejects type assertions on Response, Bun.file and shell .json() results, the same unchecked parse in another form. MCP server tests read /health through a validated readHealth helper and discovery files through parseDiscoveryInfo; the remaining tooling reads its JSON through schemas.

* test: validate the RPC request body in the CLI app export test

* test: validate CLI JSON output in the tool and app command tests

* test: compare the malformed models.dev fallback with the curated list
2026-10-04 17:01:50 +00:00

262 lines
9.6 KiB
TypeScript

import { describe, expect, test } from 'bun:test'
import { getInstanceOverride, SceneGraph, setInstanceOverride } from '@open-pencil/scene-graph'
import type { LibraryObjectStore } from '@/app/integrations/storage'
import { StorageLibraryCatalog } from '@/app/libraries/catalog/storage'
class MemoryObjects implements LibraryObjectStore {
readonly values = new Map<string, Uint8Array>()
readonly etags = new Map<string, string>()
#version = 0
async getObject(key: string) {
return this.values.get(key) ?? null
}
async getObjectValue(key: string) {
return { bytes: await this.getObject(key), etag: this.etags.get(key) ?? null }
}
async putObject(
key: string,
bytes: Uint8Array,
_contentType?: string,
options?: { ifMatch?: string; ifNoneMatch?: '*' }
) {
const current = this.etags.get(key)
if (options?.ifNoneMatch === '*' && current) throw new Error('revision conflict')
if (options?.ifMatch && options.ifMatch !== current) throw new Error('revision conflict')
this.values.set(key, new Uint8Array(bytes))
this.#version += 1
this.etags.set(key, `etag-${this.#version}`)
}
async listObjects(prefix: string) {
return [...this.values]
.filter(([key]) => key.startsWith(prefix))
.map(([key, value]) => ({ key, size: value.byteLength, etag: null }))
}
}
function sourceGraph() {
const graph = new SceneGraph()
const page = graph.getPages()[0]
graph.createNode('COMPONENT', page.id, { name: 'Button', componentKey: 'button' })
return graph
}
describe('storage library catalog', () => {
test('publishes immutable revision objects before the latest manifest', async () => {
const objects = new MemoryObjects()
const catalog = new StorageLibraryCatalog(objects)
const revision = await catalog.publishRevision({
libraryId: 'design-system',
name: 'Design system',
graph: sourceGraph(),
publishedAt: '2026-01-01T00:00:00.000Z'
})
expect([...objects.values.keys()]).toEqual([
`open-pencil/libraries/design-system/revisions/${revision.manifest.revisionId}.json`,
'open-pencil/libraries/design-system/manifest.json'
])
expect(await catalog.listLibraries()).toMatchObject([
{ libraryId: 'design-system', latestRevisionId: revision.manifest.revisionId }
])
const restored = await catalog.getRevision('design-system')
expect(restored.manifest).toEqual(revision.manifest)
expect([...restored.graph.getAllNodes()].some((node) => node.componentKey === 'button')).toBe(
true
)
})
test('preserves instance overrides through persisted revisions', async () => {
const objects = new MemoryObjects()
const catalog = new StorageLibraryCatalog(objects)
const graph = sourceGraph()
const component = [...graph.getAllNodes()].find((node) => node.componentKey === 'button')
if (!component) throw new Error('Expected component')
const nestedComponent = graph.createNode('COMPONENT', component.id, {
name: 'Icon',
componentKey: 'icon'
})
const instance = graph.createInstance(nestedComponent.id, component.id)
if (!instance) throw new Error('Expected instance')
setInstanceOverride(instance.instanceOverrides, instance.id, instance.id, 'pluginData', {
$openPencilType: 'openpencil/map',
entries: []
})
const published = await catalog.publishRevision({
libraryId: 'design-system',
name: 'Design system',
graph
})
const restored = await catalog.getRevision('design-system', published.manifest.revisionId)
const restoredInstance = [...restored.graph.getAllNodes()].find(
(node) => node.type === 'INSTANCE'
)
if (!restoredInstance) throw new Error('Expected restored instance')
expect(restoredInstance.instanceOverrides.self).toBeInstanceOf(Map)
expect(
getInstanceOverride(
restoredInstance.instanceOverrides,
restoredInstance.id,
restoredInstance.id,
'pluginData'
)
).toEqual({ $openPencilType: 'openpencil/map', entries: [] })
})
test('rejects corrupted revision content', async () => {
const objects = new MemoryObjects()
const catalog = new StorageLibraryCatalog(objects)
const revision = await catalog.publishRevision({
libraryId: 'design-system',
name: 'Design system',
graph: sourceGraph()
})
const key = `open-pencil/libraries/design-system/revisions/${revision.manifest.revisionId}.json`
const bytes = objects.values.get(key)
if (!bytes) throw new Error('Expected revision object')
const source = new TextDecoder().decode(bytes).replace('Button', 'Corrupted')
objects.values.set(key, new TextEncoder().encode(source))
await expect(
catalog.getRevision('design-system', revision.manifest.revisionId)
).rejects.toThrow('hash mismatch')
})
test('rejects malformed revision objects before deserializing them', async () => {
const objects = new MemoryObjects()
const catalog = new StorageLibraryCatalog(objects)
const revision = await catalog.publishRevision({
libraryId: 'design-system',
name: 'Design system',
graph: sourceGraph()
})
const key = `open-pencil/libraries/design-system/revisions/${revision.manifest.revisionId}.json`
for (const source of [
'{not json',
JSON.stringify({ manifest: revision.manifest, graph: { nodes: 'none' } })
]) {
objects.values.set(key, new TextEncoder().encode(source))
await expect(
catalog.getRevision('design-system', revision.manifest.revisionId)
).rejects.toThrow('Invalid component library revision')
}
})
test('rejects image bytes with missing indexes, which hashes do not cover', async () => {
const objects = new MemoryObjects()
const catalog = new StorageLibraryCatalog(objects)
const graph = sourceGraph()
const button = [...graph.getAllNodes()].find((node) => node.componentKey === 'button')
if (!button) throw new Error('Expected component')
graph.images.set('logo', new Uint8Array([17, 34, 51]))
graph.updateNode(button.id, {
fills: [
{
type: 'IMAGE',
visible: true,
opacity: 1,
color: { r: 0, g: 0, b: 0, a: 1 },
imageHash: 'logo',
imageScaleMode: 'FILL'
}
]
})
const revision = await catalog.publishRevision({
libraryId: 'design-system',
name: 'Design system',
graph
})
const key = `open-pencil/libraries/design-system/revisions/${revision.manifest.revisionId}.json`
const bytes = objects.values.get(key)
if (!bytes) throw new Error('Expected revision object')
const source = new TextDecoder().decode(bytes)
expect(source).toContain('{"$bytes":"ESIz"}')
objects.values.set(
key,
// The index-keyed form older revisions used, with byte 1 missing.
new TextEncoder().encode(source.replace('{"$bytes":"ESIz"}', '{"0":17,"2":51}'))
)
await expect(
catalog.getRevision('design-system', revision.manifest.revisionId)
).rejects.toThrow('Invalid component library revision')
})
test('rejects updates when the provider cannot return latest-manifest ETags', async () => {
const objects = new MemoryObjects()
const catalog = new StorageLibraryCatalog(objects)
const initial = await catalog.publishRevision({
libraryId: 'design-system',
name: 'Design system',
graph: sourceGraph()
})
objects.getObjectValue = async (key) => ({ bytes: await objects.getObject(key), etag: null })
await expect(
catalog.publishRevision({
libraryId: 'design-system',
name: 'Design system',
graph: sourceGraph(),
previousRevisionId: initial.manifest.revisionId
})
).rejects.toThrow('does not support conditional library publication')
})
test('allows only one concurrent latest-pointer update', async () => {
const objects = new MemoryObjects()
const first = new StorageLibraryCatalog(objects)
const second = new StorageLibraryCatalog(objects)
const initial = await first.publishRevision({
libraryId: 'design-system',
name: 'Design system',
graph: sourceGraph()
})
const delayedWrites: Array<() => void> = []
const originalPut = objects.putObject.bind(objects)
objects.putObject = async (key, bytes, contentType, options) => {
if (key.endsWith('/manifest.json')) {
await new Promise<void>((resolve) => {
delayedWrites.push(resolve)
})
}
return originalPut(key, bytes, contentType, options)
}
const publications = [first, second].map((catalog, index) =>
catalog.publishRevision({
libraryId: 'design-system',
name: 'Design system',
graph: sourceGraph(),
previousRevisionId: initial.manifest.revisionId,
description: `publisher-${index}`
})
)
while (delayedWrites.length < 2) await Bun.sleep(1)
for (const release of delayedWrites) release()
const results = await Promise.allSettled(publications)
expect(results.filter((result) => result.status === 'fulfilled')).toHaveLength(1)
expect(results.filter((result) => result.status === 'rejected')).toHaveLength(1)
})
test('rejects stale publication pointers', async () => {
const catalog = new StorageLibraryCatalog(new MemoryObjects())
await catalog.publishRevision({
libraryId: 'design-system',
name: 'Design system',
graph: sourceGraph()
})
await expect(
catalog.publishRevision({
libraryId: 'design-system',
name: 'Design system',
graph: sourceGraph(),
previousRevisionId: 'stale'
})
).rejects.toThrow('latest revision has changed')
})
})