openpencil/tests/engine/library/source-publication.test.ts
Danila Poyarkov e2a3aa3f80
fix: validate parsed JSON at untrusted boundaries with Valibot (#855)
* fix: validate parsed JSON at untrusted boundaries with Valibot

Clipboard HTML, library revisions from shared storage, MCP and automation
WebSocket messages, the MCP discovery file, sidecar output and AI/MCP tool
arguments were JSON.parse'd and cast to their expected types, so a
malformed payload reached the document or crashed paste. They now go
through v.pipe(v.string(), v.parseJson(), Schema), which reports bad JSON
and a wrong shape as the same validation failure.

The path_set tool rejects an invalid VectorNetwork and shares its parser
with create_vector. The CLI library catalog validates its files and runs
revisions through the same size, identity and content-hash checks as the
app; reading image bytes as index-keyed records also stops them coming
back empty. Hand-rolled typeof readers for plugin data, document metadata,
caches and preferences become schemas with their behaviour preserved, and
readCacheJSON takes a schema for its payload.

open-pencil/no-unvalidated-json-parse rejects type assertions on
JSON.parse results other than `as unknown` in src and packages/*/src.

* refactor: validate parsed JSON in tests and tooling

Extend open-pencil/no-unvalidated-json-parse beyond source: tests, helpers and repo tooling now parse JSON through Valibot schemas instead of asserting a type. The shared fixture reader returns a validated object; its old array annotation never matched the fixtures.

* fix: validate clipboard geometry bytes, library images and model catalogs

Clipboard geometry blobs and library image bytes must be bytes at contiguous indexes, so out-of-range or gapped values are rejected instead of silently becoming different geometry or images; serialized library nodes must carry source metadata. The models.dev and OpenRouter responses are validated like their cached copies, and activate-tab rejects a CDP frame it cannot read instead of hanging.

* refactor: extend the JSON validation lint to .json() results

no-unvalidated-json-parse now also rejects type assertions on Response, Bun.file and shell .json() results, the same unchecked parse in another form. MCP server tests read /health through a validated readHealth helper and discovery files through parseDiscoveryInfo; the remaining tooling reads its JSON through schemas.

* test: validate the RPC request body in the CLI app export test

* test: validate CLI JSON output in the tool and app command tests

* test: compare the malformed models.dev fallback with the curated list
2026-10-04 17:01:50 +00:00

68 lines
2.1 KiB
TypeScript

import { describe, expect, test } from 'bun:test'
import { exportFigFile, initCodec, parseFigFile } from '@open-pencil/core'
import {
readSourceLibraryPublication,
writeSourceLibraryPublication
} from '@open-pencil/core/library'
import { SceneGraph } from '@open-pencil/scene-graph'
describe('source library publication identity', () => {
test('survives a FIG export and reimport', async () => {
initCodec()
const graph = new SceneGraph()
writeSourceLibraryPublication(graph, {
libraryId: 'design-system',
revisionId: 'revision-1',
name: 'Design system',
catalogSource: 'local'
})
const restored = await parseFigFile((await exportFigFile(graph)).buffer as ArrayBuffer)
expect(readSourceLibraryPublication(restored)).toEqual({
libraryId: 'design-system',
revisionId: 'revision-1',
name: 'Design system',
catalogSource: 'local'
})
})
test('round-trips through root plugin data', () => {
const graph = new SceneGraph()
expect(readSourceLibraryPublication(graph)).toBeNull()
writeSourceLibraryPublication(graph, {
libraryId: 'design-system',
revisionId: 'revision-1',
name: 'Design system',
catalogSource: 'local'
})
expect(readSourceLibraryPublication(graph)).toEqual({
libraryId: 'design-system',
revisionId: 'revision-1',
name: 'Design system',
catalogSource: 'local'
})
})
test('ignores malformed metadata', () => {
const graph = new SceneGraph()
const root = graph.getNode(graph.rootId)
if (!root) throw new Error('Root missing')
for (const value of [
'{}',
'{not json',
JSON.stringify({ libraryId: 'design-system', revisionId: 'revision-1', name: 1 }),
JSON.stringify({
libraryId: 'design-system',
revisionId: 'revision-1',
name: 'Design system',
catalogSource: 7
})
]) {
graph.updateNode(root.id, {
pluginData: [{ pluginId: 'open-pencil', key: 'sourceLibraryPublication', value }]
})
expect(readSourceLibraryPublication(graph)).toBeNull()
}
})
})