openpencil/tests/engine/tools
Danila Poyarkov 99925e4c25
fix(tools): evaluate calc expressions without expr-eval (#753)
* fix(tools): evaluate calc expressions without expr-eval

expr-eval has an unpatched critical advisory for code execution through
toJSFunction(), which compiles expressions with new Function
(GHSA-q9v2-7m5w-4693). The advisory covers every published version, so
`bun run check:audit` fails on every branch and `bun audit fix` has nothing
to upgrade to. The calc tool only ever called evaluate(), so the advisory's
own vector was not reachable, but the dependency stays flagged and the
evaluator's surface was far wider than the tool documents: random(), factorials,
trigonometry, constants, strings, array indexing, property access and
statement sequences all evaluated, while the documented ** operator did not
parse at all, since expr-eval spells power as ^.

Replace it with a recursive-descent evaluator for exactly the documented
grammar. It compiles nothing, reaches no host object, and fixes **, which is
right-associative and binds tighter than a leading sign, so -2 ** 2 is -4 as
in ordinary notation. Non-finite results are still reported by the tool rather
than the evaluator, so 1 / 0 keeps its "Produced Infinity" message.

The tool had no tests; both the evaluator and the tool's JSON-array and
error-reporting paths are covered now.

* refactor(tools): parse calc expressions with jsep

Replace the hand-written tokenizer and recursive-descent parser with jsep,
a maintained zero-dependency expression parser with no advisory history, and
keep only the tree walk: an allowlist of node types, arithmetic operators and
the documented functions. Parsing, where the vulnerabilities in this class of
library live, is no longer ours to maintain.

Behaviour follows the parser rather than the previous hand-written precedence,
so a leading sign now binds tighter than '**' and '-2 ** 2' is 4; the tests
pin that alongside right-associativity. Parse errors keep jsep's own wording
and character positions.

* fix(tools): reject inherited names and fold long calc argument lists

Two findings from review of this branch. The function lookup used `in`, so
an inherited key such as `constructor(1)` passed the guard and then failed
while destructuring a missing arity, reporting a TypeError instead of an
unknown function; it now uses Object.hasOwn. min and max spread their
arguments, which overflows the call stack on V8 at roughly 125k arguments,
so they fold instead. Both paths are covered by tests.
2026-09-25 01:44:46 +04:00
..
analyze/overlaps test(tools): create control-case node on the plain graph 2026-06-19 11:47:37 +10:00
calc fix(tools): evaluate calc expressions without expr-eval (#753) 2026-09-25 01:44:46 +04:00
modify chore: format codebase 2026-05-24 12:15:29 +03:00
stock-photo fix: protect unsaved documents and defer credential access (#713) 2026-09-17 15:25:15 +03:00
xpath test(engine): move root tests into domains 2026-05-16 12:30:27 +03:00
ai-adapter.test.ts refactor(tools): default interface exposure to inclusion 2026-09-15 17:12:31 +03:00
cli.test.ts ci: shard unit tests by owner and cut the quick suite from 100 s to 13 s (#715) 2026-09-17 10:18:16 +03:00
create.test.ts refactor(tools)!: centralize schemas and execution contracts 2026-09-15 10:55:27 +03:00
describe.test.ts fix(tools): describe visible strokes (#447) 2026-08-01 17:40:30 +03:00
eval-wrap.test.ts refactor(tools): use acorn AST parser for eval wrapping 2026-05-11 12:15:38 +03:00
export-image.test.ts feat(ai): add isolated visual inspection 2026-08-13 21:15:44 +03:00
input.test.ts fix(tools): preserve atomic property state and validate inputs 2026-09-15 16:47:37 +03:00
library-components.test.ts feat: add Figma-style variants and component libraries (#512) 2026-08-14 19:31:41 +03:00
modify.test.ts chore(tests): guard modify tool assertions 2026-05-06 11:20:49 +03:00
read.test.ts ci: shard unit tests by owner and cut the quick suite from 100 s to 13 s (#715) 2026-09-17 10:18:16 +03:00
registry.test.ts refactor(tools): default interface exposure to inclusion 2026-09-15 17:12:31 +03:00
structure.test.ts chore(tests): remove targeted non-null assertions 2026-05-06 03:13:58 +03:00