openpencil/tests/engine/tools/calc/tool.test.ts
Danila Poyarkov e2a3aa3f80
fix: validate parsed JSON at untrusted boundaries with Valibot (#855)
* fix: validate parsed JSON at untrusted boundaries with Valibot

Clipboard HTML, library revisions from shared storage, MCP and automation
WebSocket messages, the MCP discovery file, sidecar output and AI/MCP tool
arguments were JSON.parse'd and cast to their expected types, so a
malformed payload reached the document or crashed paste. They now go
through v.pipe(v.string(), v.parseJson(), Schema), which reports bad JSON
and a wrong shape as the same validation failure.

The path_set tool rejects an invalid VectorNetwork and shares its parser
with create_vector. The CLI library catalog validates its files and runs
revisions through the same size, identity and content-hash checks as the
app; reading image bytes as index-keyed records also stops them coming
back empty. Hand-rolled typeof readers for plugin data, document metadata,
caches and preferences become schemas with their behaviour preserved, and
readCacheJSON takes a schema for its payload.

open-pencil/no-unvalidated-json-parse rejects type assertions on
JSON.parse results other than `as unknown` in src and packages/*/src.

* refactor: validate parsed JSON in tests and tooling

Extend open-pencil/no-unvalidated-json-parse beyond source: tests, helpers and repo tooling now parse JSON through Valibot schemas instead of asserting a type. The shared fixture reader returns a validated object; its old array annotation never matched the fixtures.

* fix: validate clipboard geometry bytes, library images and model catalogs

Clipboard geometry blobs and library image bytes must be bytes at contiguous indexes, so out-of-range or gapped values are rejected instead of silently becoming different geometry or images; serialized library nodes must carry source metadata. The models.dev and OpenRouter responses are validated like their cached copies, and activate-tab rejects a CDP frame it cannot read instead of hanging.

* refactor: extend the JSON validation lint to .json() results

no-unvalidated-json-parse now also rejects type assertions on Response, Bun.file and shell .json() results, the same unchecked parse in another form. MCP server tests read /health through a validated readHealth helper and discovery files through parseDiscoveryInfo; the remaining tooling reads its JSON through schemas.

* test: validate the RPC request body in the CLI app export test

* test: validate CLI JSON output in the tool and app command tests

* test: compare the malformed models.dev fallback with the curated list
2026-10-04 17:01:50 +00:00

67 lines
2.3 KiB
TypeScript

import { describe, expect, test } from 'bun:test'
import { getTool, setupToolTest, type ToolResult } from '#tests/helpers/tools'
function run(expr: string): ToolResult {
const { figma } = setupToolTest()
return getTool('calc').execute(figma, { expr }) as ToolResult
}
describe('calc tool', () => {
test('returns a single result for one expression', () => {
expect(run('844 - 56 - 96 - 82')).toEqual({ expr: '844 - 56 - 96 - 82', result: 610 })
})
test('evaluates a JSON array in one call, preserving order', () => {
expect(run('["1440 * 8 / 12", "(952 - 16) / 2", "floor(390 * 0.6)"]')).toEqual({
results: [
{ expr: '1440 * 8 / 12', result: 960 },
{ expr: '(952 - 16) / 2', result: 468 },
{ expr: 'floor(390 * 0.6)', result: 234 }
]
})
})
test('treats a single-element array like a bare expression', () => {
expect(run('["2 + 2"]')).toEqual({ expr: '2 + 2', result: 4 })
})
test('reports the documented ** operator', () => {
expect(run('2 ** 10')).toEqual({ expr: '2 ** 10', result: 1024 })
})
test('reports a non-finite result as an error rather than a number', () => {
expect(run('1 / 0')).toEqual({ expr: '1 / 0', error: 'Produced Infinity' })
expect(run('0 / 0')).toEqual({ expr: '0 / 0', error: 'Produced NaN' })
})
test('reports a rejected expression without failing its siblings', () => {
const result = run('["2 + 2", "2 +", "3 * 3"]')
expect(result.results).toEqual([
{ expr: '2 + 2', result: 4 },
{ expr: '2 +', error: 'Expected expression after + at character 3' },
{ expr: '3 * 3', result: 9 }
])
})
test('evaluates text that only looks like JSON as an expression', () => {
expect(run('2 + 2')).toEqual({ expr: '2 + 2', result: 4 })
expect((run('{"a": 1}') as { error: string }).error).toContain('Unexpected "{"')
})
test('rejects a JSON array that contains anything but expressions', () => {
expect(run('["2 + 2", 3]')).toEqual({
expr: '["2 + 2", 3]',
error: 'A JSON array of expressions must contain only strings'
})
})
test('advertises exactly the functions it supports', () => {
const { description } = getTool('calc')
for (const name of ['min', 'max', 'floor', 'ceil', 'round', 'abs', 'sqrt', 'pow']) {
expect(description).toContain(name)
}
expect(description).toContain('**')
})
})