* fix: validate parsed JSON at untrusted boundaries with Valibot Clipboard HTML, library revisions from shared storage, MCP and automation WebSocket messages, the MCP discovery file, sidecar output and AI/MCP tool arguments were JSON.parse'd and cast to their expected types, so a malformed payload reached the document or crashed paste. They now go through v.pipe(v.string(), v.parseJson(), Schema), which reports bad JSON and a wrong shape as the same validation failure. The path_set tool rejects an invalid VectorNetwork and shares its parser with create_vector. The CLI library catalog validates its files and runs revisions through the same size, identity and content-hash checks as the app; reading image bytes as index-keyed records also stops them coming back empty. Hand-rolled typeof readers for plugin data, document metadata, caches and preferences become schemas with their behaviour preserved, and readCacheJSON takes a schema for its payload. open-pencil/no-unvalidated-json-parse rejects type assertions on JSON.parse results other than `as unknown` in src and packages/*/src. * refactor: validate parsed JSON in tests and tooling Extend open-pencil/no-unvalidated-json-parse beyond source: tests, helpers and repo tooling now parse JSON through Valibot schemas instead of asserting a type. The shared fixture reader returns a validated object; its old array annotation never matched the fixtures. * fix: validate clipboard geometry bytes, library images and model catalogs Clipboard geometry blobs and library image bytes must be bytes at contiguous indexes, so out-of-range or gapped values are rejected instead of silently becoming different geometry or images; serialized library nodes must carry source metadata. The models.dev and OpenRouter responses are validated like their cached copies, and activate-tab rejects a CDP frame it cannot read instead of hanging. * refactor: extend the JSON validation lint to .json() results no-unvalidated-json-parse now also rejects type assertions on Response, Bun.file and shell .json() results, the same unchecked parse in another form. MCP server tests read /health through a validated readHealth helper and discovery files through parseDiscoveryInfo; the remaining tooling reads its JSON through schemas. * test: validate the RPC request body in the CLI app export test * test: validate CLI JSON output in the tool and app command tests * test: compare the malformed models.dev fallback with the curated list
41 lines
1.6 KiB
TypeScript
41 lines
1.6 KiB
TypeScript
import { expect, test } from 'bun:test'
|
|
|
|
import { materializeFigFragment } from '@open-pencil/fig'
|
|
import { prepareGraphTransfer, applyGraphTransfer, SceneGraph } from '@open-pencil/scene-graph'
|
|
|
|
import { readFixtureObject } from '#tests/helpers/fig/fixtures'
|
|
|
|
const fixture = readFixtureObject('nested-binding-ownership-records.json')
|
|
|
|
test('prepares a real FIG fragment without mutating the destination', () => {
|
|
const fragment = materializeFigFragment(
|
|
fixture.nodeChanges,
|
|
fixture.blobs.map((value) => Uint8Array.fromBase64(value))
|
|
)
|
|
const target = new SceneGraph()
|
|
const before = [...target.nodes.keys()]
|
|
const plan = prepareGraphTransfer({
|
|
source: fragment.graph,
|
|
rootIds: fragment.rootIds,
|
|
dependencyPageIds: fragment.dependencyPageIds,
|
|
target,
|
|
parentId: target.getPages()[0].id
|
|
})
|
|
expect([...target.nodes.keys()]).toEqual(before)
|
|
expect(plan.rootIds).toHaveLength(fragment.rootIds.length)
|
|
expect(plan.nodes.length).toBeGreaterThan(plan.rootIds.length)
|
|
const ids = new Set(plan.nodes.map((node) => node.id))
|
|
for (const node of plan.nodes)
|
|
if (node.props.componentId) expect(ids.has(node.props.componentId)).toBe(true)
|
|
expect(plan.variables.length).toBeGreaterThan(0)
|
|
applyGraphTransfer(target, plan)
|
|
expect(plan.rootIds.every((id) => target.getNode(id))).toBe(true)
|
|
for (const node of plan.nodes) {
|
|
const inserted = target.getNode(node.id)
|
|
expect(inserted?.parentId).toBe(node.parentId)
|
|
if (inserted?.componentId) expect(target.getNode(inserted.componentId)).toBeDefined()
|
|
}
|
|
expect(target.variables.size).toBe(plan.variables.length)
|
|
expect(target.activeMode).toEqual(plan.activeModes)
|
|
})
|