* fix: validate parsed JSON at untrusted boundaries with Valibot Clipboard HTML, library revisions from shared storage, MCP and automation WebSocket messages, the MCP discovery file, sidecar output and AI/MCP tool arguments were JSON.parse'd and cast to their expected types, so a malformed payload reached the document or crashed paste. They now go through v.pipe(v.string(), v.parseJson(), Schema), which reports bad JSON and a wrong shape as the same validation failure. The path_set tool rejects an invalid VectorNetwork and shares its parser with create_vector. The CLI library catalog validates its files and runs revisions through the same size, identity and content-hash checks as the app; reading image bytes as index-keyed records also stops them coming back empty. Hand-rolled typeof readers for plugin data, document metadata, caches and preferences become schemas with their behaviour preserved, and readCacheJSON takes a schema for its payload. open-pencil/no-unvalidated-json-parse rejects type assertions on JSON.parse results other than `as unknown` in src and packages/*/src. * refactor: validate parsed JSON in tests and tooling Extend open-pencil/no-unvalidated-json-parse beyond source: tests, helpers and repo tooling now parse JSON through Valibot schemas instead of asserting a type. The shared fixture reader returns a validated object; its old array annotation never matched the fixtures. * fix: validate clipboard geometry bytes, library images and model catalogs Clipboard geometry blobs and library image bytes must be bytes at contiguous indexes, so out-of-range or gapped values are rejected instead of silently becoming different geometry or images; serialized library nodes must carry source metadata. The models.dev and OpenRouter responses are validated like their cached copies, and activate-tab rejects a CDP frame it cannot read instead of hanging. * refactor: extend the JSON validation lint to .json() results no-unvalidated-json-parse now also rejects type assertions on Response, Bun.file and shell .json() results, the same unchecked parse in another form. MCP server tests read /health through a validated readHealth helper and discovery files through parseDiscoveryInfo; the remaining tooling reads its JSON through schemas. * test: validate the RPC request body in the CLI app export test * test: validate CLI JSON output in the tool and app command tests * test: compare the malformed models.dev fallback with the curated list
41 lines
1.7 KiB
TypeScript
41 lines
1.7 KiB
TypeScript
import { describe, expect, test } from 'bun:test'
|
|
|
|
import { lint, ruleDiagnostics } from './helpers/lint.ts'
|
|
|
|
const rule = 'no-unvalidated-json-parse'
|
|
const rules = { [`open-pencil/${rule}`]: 'error' }
|
|
|
|
describe('no-unvalidated-json-parse', () => {
|
|
test.each([
|
|
'type Foo = { a: number }; JSON.parse(text) as Foo',
|
|
'type Foo = { a: number }; <Foo>JSON.parse(text)',
|
|
'JSON.parse(text) as { a: number }',
|
|
'JSON.parse(text) as unknown as string[]',
|
|
'(JSON.parse(text)) as Record<string, unknown>',
|
|
'globalThis.JSON.parse(text) as string[]',
|
|
"JSON['parse'](text) as string[]",
|
|
'declare const response: Response; (await response.json()) as { a: number }',
|
|
'declare const response: Response; response.json() as Promise<string[]>',
|
|
'declare const file: { json(): Promise<unknown> }; (await file.json()) as string[]'
|
|
])('rejects %s', async (source) => {
|
|
expect(
|
|
ruleDiagnostics(await lint(`declare const text: string; ${source}`, rules), rule)
|
|
).toHaveLength(1)
|
|
})
|
|
|
|
test.each([
|
|
'JSON.parse(text) as unknown',
|
|
'const value: unknown = JSON.parse(text)',
|
|
'JSON.stringify(text) as string',
|
|
'const JSON = { parse: (value: string) => value }; JSON.parse(text) as string',
|
|
'type Foo = { a: number }; declare const value: unknown; value as Foo',
|
|
'declare const response: Response; (await response.json()) as unknown',
|
|
'declare const response: Response; response.json() as Promise<unknown>',
|
|
'declare const api: { json(key: string): unknown }; api.json(text) as string'
|
|
])('accepts %s', async (source) => {
|
|
expect(
|
|
ruleDiagnostics(await lint(`declare const text: string; ${source}`, rules), rule)
|
|
).toHaveLength(0)
|
|
})
|
|
})
|