openpencil/tests/e2e
Danila Poyarkov e2a3aa3f80
fix: validate parsed JSON at untrusted boundaries with Valibot (#855)
* fix: validate parsed JSON at untrusted boundaries with Valibot

Clipboard HTML, library revisions from shared storage, MCP and automation
WebSocket messages, the MCP discovery file, sidecar output and AI/MCP tool
arguments were JSON.parse'd and cast to their expected types, so a
malformed payload reached the document or crashed paste. They now go
through v.pipe(v.string(), v.parseJson(), Schema), which reports bad JSON
and a wrong shape as the same validation failure.

The path_set tool rejects an invalid VectorNetwork and shares its parser
with create_vector. The CLI library catalog validates its files and runs
revisions through the same size, identity and content-hash checks as the
app; reading image bytes as index-keyed records also stops them coming
back empty. Hand-rolled typeof readers for plugin data, document metadata,
caches and preferences become schemas with their behaviour preserved, and
readCacheJSON takes a schema for its payload.

open-pencil/no-unvalidated-json-parse rejects type assertions on
JSON.parse results other than `as unknown` in src and packages/*/src.

* refactor: validate parsed JSON in tests and tooling

Extend open-pencil/no-unvalidated-json-parse beyond source: tests, helpers and repo tooling now parse JSON through Valibot schemas instead of asserting a type. The shared fixture reader returns a validated object; its old array annotation never matched the fixtures.

* fix: validate clipboard geometry bytes, library images and model catalogs

Clipboard geometry blobs and library image bytes must be bytes at contiguous indexes, so out-of-range or gapped values are rejected instead of silently becoming different geometry or images; serialized library nodes must carry source metadata. The models.dev and OpenRouter responses are validated like their cached copies, and activate-tab rejects a CDP frame it cannot read instead of hanging.

* refactor: extend the JSON validation lint to .json() results

no-unvalidated-json-parse now also rejects type assertions on Response, Bun.file and shell .json() results, the same unchecked parse in another form. MCP server tests read /health through a validated readHealth helper and discovery files through parseDiscoveryInfo; the remaining tooling reads its JSON through schemas.

* test: validate the RPC request body in the CLI app export test

* test: validate CLI JSON output in the tool and app command tests

* test: compare the malformed models.dev fallback with the curated list
2026-10-04 17:01:50 +00:00
..
app feat(app): jump between pages from the command palette (#801) 2026-10-01 20:26:35 +04:00
brand feat: refresh branding with generated platform icons (#707) 2026-09-16 11:54:07 +03:00
canvas fix: validate parsed JSON at untrusted boundaries with Valibot (#855) 2026-10-04 17:01:50 +00:00
chat feat(app): show who works on each page (#815) 2026-10-04 01:18:16 +04:00
clipboard test(clipboard): open a document in the Tauri fixture 2026-09-16 14:00:30 +03:00
code feat(lint): suggest group-to-frame and hidden-layer fixes; keep canvas edits in code previews (#870) 2026-10-04 12:46:06 +00:00
collab feat(app): follow people and agents from the toolbar avatars (#807) 2026-10-04 00:09:40 +04:00
color-picker fix: validate parsed JSON at untrusted boundaries with Valibot (#855) 2026-10-04 17:01:50 +00:00
components fix: validate parsed JSON at untrusted boundaries with Valibot (#855) 2026-10-04 17:01:50 +00:00
context-menu test(app): stabilize final interaction coverage 2026-07-20 16:34:16 +03:00
design perf(properties): retain inactive panels safely 2026-09-15 17:01:44 +03:00
design-check feat: check designs live with a Lint panel, canvas markers, and fixes (#804) 2026-10-04 10:08:39 +00:00
dom-css
editor refactor: scope browser test instrumentation and global types (#667) 2026-09-10 14:26:36 +03:00
export refactor(export): derive export format lists from the IO registry (#755) 2026-09-25 15:42:42 +04:00
fonts fix(text): render variable font styles at their named instances (#773) 2026-09-26 11:25:01 +04:00
keyboard fix: validate parsed JSON at untrusted boundaries with Valibot (#855) 2026-10-04 17:01:50 +00:00
layers feat(demo): rebuild the first page as a component library with staged loading (#717) 2026-09-18 08:18:21 +03:00
native fix: validate parsed JSON at untrusted boundaries with Valibot (#855) 2026-10-04 17:01:50 +00:00
pages Release v0.14.0 2026-08-10 11:40:44 +03:00
panels feat(vue): add responsive property grids 2026-07-26 12:42:50 +03:00
perf test: honor the configured browser test origin 2026-09-16 12:46:13 +03:00
properties feat(scene-graph)!: make a stroke a paint (#864) 2026-10-04 13:38:05 +04:00
scene test: honor the configured browser test origin 2026-09-16 12:46:13 +03:00
settings feat(settings): configure tool access, MCP failures, and step limits 2026-09-17 23:55:58 +03:00
snap test(snapping): verify pixel rounding without guides 2026-09-13 14:02:16 +03:00
storage refactor(ui): compose shared editor controls (#670) 2026-09-10 12:09:06 +03:00
storybook fix: validate parsed JSON at untrusted boundaries with Valibot (#855) 2026-10-04 17:01:50 +00:00
stroke-picker fix(core): draw gradient and image strokes as the paint they are (#868) 2026-10-04 13:25:45 +00:00
text test: honor the configured browser test origin 2026-09-16 12:46:13 +03:00
toolbar test: seed motion preferences through Playwright storage state 2026-09-10 23:24:06 +03:00
tools
ui test(ui): keep runtime theme import dependency-safe 2026-07-20 14:07:32 +03:00
variables fix(app): polish variable dialog states 2026-07-18 05:25:40 +03:00
vectorize feat(app): convert image layers to vectors 2026-07-27 16:22:05 +03:00
viewport
autosave.spec.ts fix(app): retain recovery after closing unsaved tabs (#505) 2026-08-13 21:39:35 +03:00
components.spec.ts
fixtures.ts test(app): stabilize final interaction coverage 2026-07-20 16:34:16 +03:00
recovery.spec.ts fix: protect unsaved documents and defer credential access (#713) 2026-09-17 15:25:15 +03:00