fix(#2182): harden registry rendering + validation against injection (review)
Addresses findings from the orthogonal /code-review + /security-review passes: - Markdown-injection (CRITICAL/HIGH): escape untrusted free-text (name, description, license, author, eos axes) with mdInline() and size install/uninstall code fences dynamically so a crafted entry cannot inject phishing links, break the summary table, or escape the code fence in the committed, GitHub-rendered catalog. - validateEntries no longer throws on a null/non-object array element (kept the --json contract); rejects control characters in free-text fields; caps field lengths and entry count; tightens the discussion and license regexes so neither admits Markdown metacharacters / newlines. - gen-registry treats a missing capabilities.json as an error (only eos.json is optional pre-PR2); disambiguated from gen-capability-registry.cjs. - Renders the required 'author' field (was captured but never shown). - Adds tests for every fix: escaping/link-hijack/fence, null guard, control chars, length + entry caps, tightened regexes, eos render path, interactions guards. Refs #2182 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -7,6 +7,15 @@
|
||||
* from the corresponding source JSON, via registry-schema.cjs#renderMarkdown.
|
||||
* Issue #2182.
|
||||
*
|
||||
* NOT to be confused with `scripts/gen-capability-registry.cjs`: that script
|
||||
* generates the RUNTIME capability manifest consumed by the host at runtime
|
||||
* (`gsd-core/bin/lib/capability-registry.cjs`, built from every
|
||||
* `capabilities/<id>/capability.json` declaration). THIS script instead
|
||||
* generates the human-facing DOCUMENTATION catalog pages
|
||||
* (`docs/registries/*.md`) from the third-party discoverability registry
|
||||
* source JSON (`docs/registries/{capabilities,eos}.json`). The two pipelines
|
||||
* are independent — do not conflate them.
|
||||
*
|
||||
* Usage:
|
||||
* node scripts/gen-registry.cjs # print rendered markdown(s) to stdout
|
||||
* node scripts/gen-registry.cjs --write # write the *-registry.md file(s)
|
||||
@@ -46,8 +55,14 @@ function getRegistriesDir() {
|
||||
|
||||
/**
|
||||
* Render the markdown for a single registry type from its committed source
|
||||
* JSON. Returns null if the source JSON does not exist (e.g. eos.json before
|
||||
* PR2 ships) — callers treat that as "nothing to do" rather than an error.
|
||||
* JSON.
|
||||
*
|
||||
* Only `eos.json` is optional (pre-PR2, before that source JSON ships) —
|
||||
* an absent `eos.json` returns null and callers treat that as "nothing to
|
||||
* do". `capabilities.json` is the primary registry source: a missing
|
||||
* `capabilities.json` is ALWAYS an error (never a silent "up to date"
|
||||
* pass), mirroring the type distinction in `scripts/validate-registry.cjs`
|
||||
* (`type === 'eos' && !exists → continue`).
|
||||
*
|
||||
* @param {'capability'|'eos'} type
|
||||
* @returns {string|null}
|
||||
@@ -57,7 +72,13 @@ function renderFor(type) {
|
||||
if (!source) throw new Error(`gen-registry: unknown registry type "${type}"`);
|
||||
|
||||
const jsonPath = path.join(getRegistriesDir(), source.jsonFile);
|
||||
if (!fs.existsSync(jsonPath)) return null;
|
||||
if (!fs.existsSync(jsonPath)) {
|
||||
if (type === 'eos') return null;
|
||||
throw new ExitError(
|
||||
1,
|
||||
`${source.jsonFile} does not exist at ${jsonPath}. Run:\n node scripts/gen-registry.cjs --write\n(after adding docs/registries/${source.jsonFile})`,
|
||||
);
|
||||
}
|
||||
|
||||
const entries = JSON.parse(fs.readFileSync(jsonPath, 'utf8'));
|
||||
return renderMarkdown(entries, { type, sourceFile: source.jsonFile });
|
||||
|
||||
@@ -122,6 +122,21 @@ const EOS_REQUIRED = Object.freeze([
|
||||
'protocolVersion',
|
||||
]);
|
||||
|
||||
// Escape Markdown inline metacharacters in UNTRUSTED free text so a registry
|
||||
// entry cannot inject links/tables/code-spans into the generated catalog.
|
||||
// Neutralizes: link hijack ([ ] ( )), table breakout (|), code span (`),
|
||||
// and backslash. Newlines are collapsed to a single space (inline contexts).
|
||||
function mdInline(value) {
|
||||
return String(value).replace(/[\\`*_[\]()|~<>]/g, '\\$&').replace(/[\r\n]+/g, ' ');
|
||||
}
|
||||
// A fenced-code fence guaranteed longer than any backtick run in `value`, so a
|
||||
// value containing ``` cannot escape the block (CommonMark rule). Min length 3.
|
||||
function fenceFor(value) {
|
||||
const runs = String(value).match(/`+/g) || [];
|
||||
const longest = runs.reduce((m, r) => Math.max(m, r.length), 0);
|
||||
return '`'.repeat(Math.max(3, longest + 1));
|
||||
}
|
||||
|
||||
// A single `engines.gsd` range clause: optional comparison operator, optional
|
||||
// leading `v`, exactly three dot-separated numeric segments, optional
|
||||
// prerelease (`-...`) and build (`+...`) suffixes. Operator alternation order
|
||||
@@ -244,6 +259,8 @@ function validateEosInteractions(interactions, addError) {
|
||||
if (allowedValues === AXES_FREE_STRING) {
|
||||
if (typeof v !== 'string' || v.trim() === '') {
|
||||
addError(`interactions.axes.${key}`, 'must be a non-empty string');
|
||||
} else if (v.length > 300) {
|
||||
addError(`interactions.axes.${key}`, 'exceeds max length 300');
|
||||
}
|
||||
} else if (typeof v !== 'string' || !allowedValues.includes(v)) {
|
||||
addError(`interactions.axes.${key}`, `must be one of the allowed values for ${key}`);
|
||||
@@ -267,6 +284,12 @@ function validateEntries(entries, opts) {
|
||||
return { ok: false, errors: [{ index: -1, field: '(root)', reason: 'entries must be an array' }] };
|
||||
}
|
||||
|
||||
// Entry-count cap: a pathologically large array (e.g. from an automated or
|
||||
// malicious PR) is rejected wholesale rather than validated entry-by-entry.
|
||||
if (entries.length > 2000) {
|
||||
return { ok: false, errors: [{ index: -1, field: '(root)', reason: 'too many entries (max 2000)' }] };
|
||||
}
|
||||
|
||||
const required = opts.type === 'eos' ? EOS_REQUIRED : CAPABILITY_REQUIRED;
|
||||
const requiredSet = new Set(required);
|
||||
const seenIds = new Set();
|
||||
@@ -275,10 +298,18 @@ function validateEntries(entries, opts) {
|
||||
entries.forEach((entry, index) => {
|
||||
const addError = (field, reason) => {
|
||||
const err = { index, field, reason };
|
||||
if (typeof entry.id === 'string') err.id = entry.id;
|
||||
if (entry && typeof entry === 'object' && typeof entry.id === 'string') err.id = entry.id;
|
||||
errors.push(err);
|
||||
};
|
||||
|
||||
// Null/non-object element guard — a malformed array element (null,
|
||||
// undefined-via-hole, a primitive, or an array) cannot be destructured by
|
||||
// the field checks below, so reject it outright rather than throwing.
|
||||
if (entry === null || typeof entry !== 'object' || Array.isArray(entry)) {
|
||||
addError('(entry)', 'entry must be a JSON object');
|
||||
return;
|
||||
}
|
||||
|
||||
for (const key of Object.keys(entry)) {
|
||||
if (!requiredSet.has(key)) addError(key, 'unknown field');
|
||||
}
|
||||
@@ -291,6 +322,35 @@ function validateEntries(entries, opts) {
|
||||
}
|
||||
}
|
||||
|
||||
// Control-character rejection (defense in depth): `allowTabNewline` widens
|
||||
// the reject-set exception for the two shell-snippet fields (install/
|
||||
// uninstall), which legitimately contain tabs/newlines; every other free
|
||||
// text field disallows ALL C0 control characters plus DEL (incl. \n/\t).
|
||||
// Checked via char codes (not a literal control-char regex range) — same
|
||||
// approach as capability-validator.cjs's hooks[].matcher check, which
|
||||
// avoids tripping ESLint's no-control-regex rule.
|
||||
const hasDisallowedControlChar = (v, allowTabNewline) => {
|
||||
for (let c = 0; c < v.length; c += 1) {
|
||||
const code = v.charCodeAt(c);
|
||||
if (allowTabNewline && (code === 0x09 || code === 0x0a)) continue;
|
||||
if (code < 0x20 || code === 0x7f) return true;
|
||||
}
|
||||
return false;
|
||||
};
|
||||
const checkNoControlChars = (field, allowTabNewline) => {
|
||||
if (missing.has(field)) return;
|
||||
const v = entry[field];
|
||||
if (typeof v !== 'string') return;
|
||||
if (hasDisallowedControlChar(v, allowTabNewline)) addError(field, 'must not contain control characters');
|
||||
};
|
||||
// Length cap: reject oversized fields (untrusted third-party input feeding
|
||||
// a committed Markdown catalog should not be allowed to blow up the doc).
|
||||
const checkMaxLength = (field, max) => {
|
||||
if (missing.has(field)) return;
|
||||
const v = entry[field];
|
||||
if (typeof v === 'string' && v.length > max) addError(field, `exceeds max length ${max}`);
|
||||
};
|
||||
|
||||
if (!missing.has('id')) {
|
||||
const id = entry.id;
|
||||
if (typeof id !== 'string' || !/^[a-z0-9]+(-[a-z0-9]+)*$/.test(id)) {
|
||||
@@ -302,12 +362,17 @@ function validateEntries(entries, opts) {
|
||||
seenIds.add(id);
|
||||
}
|
||||
}
|
||||
checkMaxLength('id', 100);
|
||||
|
||||
for (const field of ['name', 'description', 'author']) {
|
||||
if (missing.has(field)) continue;
|
||||
const v = entry[field];
|
||||
if (typeof v !== 'string' || v.trim() === '') addError(field, 'must be a non-empty string');
|
||||
checkNoControlChars(field, false);
|
||||
}
|
||||
checkMaxLength('name', 120);
|
||||
checkMaxLength('author', 120);
|
||||
checkMaxLength('description', 1000);
|
||||
|
||||
if (!missing.has('type') && entry.type !== opts.type) {
|
||||
addError('type', `type must be "${opts.type}"`);
|
||||
@@ -318,30 +383,37 @@ function validateEntries(entries, opts) {
|
||||
addError('repo', 'repo must be in "owner/repo" form');
|
||||
}
|
||||
}
|
||||
checkMaxLength('repo', 100);
|
||||
|
||||
if (!missing.has('license')) {
|
||||
const v = entry.license;
|
||||
if (typeof v !== 'string' || v.trim() === '' || !/^[A-Za-z0-9.+()\-\s]+$/.test(v)) {
|
||||
if (typeof v !== 'string' || v.trim() === '' || !/^[A-Za-z0-9.+()\- ]+$/.test(v)) {
|
||||
addError('license', 'license must be a non-empty SPDX-like string');
|
||||
}
|
||||
}
|
||||
checkMaxLength('license', 120);
|
||||
|
||||
if (!missing.has('enginesGsd') && !isValidGsdRange(entry.enginesGsd)) {
|
||||
addError('enginesGsd', 'enginesGsd must be a valid semver range');
|
||||
}
|
||||
checkMaxLength('enginesGsd', 100);
|
||||
|
||||
for (const field of ['install', 'uninstall']) {
|
||||
if (missing.has(field)) continue;
|
||||
const v = entry[field];
|
||||
if (typeof v !== 'string' || v.trim() === '') addError(field, 'must be a non-empty string');
|
||||
checkNoControlChars(field, true);
|
||||
}
|
||||
checkMaxLength('install', 2000);
|
||||
checkMaxLength('uninstall', 2000);
|
||||
|
||||
if (!missing.has('discussion')) {
|
||||
const v = entry.discussion;
|
||||
if (typeof v !== 'string' || !/^https:\/\/github\.com\/[^/\s]+\/[^/\s]+\/discussions\/\d+$/.test(v)) {
|
||||
if (typeof v !== 'string' || !/^https:\/\/github\.com\/[A-Za-z0-9_.-]+\/[A-Za-z0-9_.-]+\/discussions\/\d+$/.test(v)) {
|
||||
addError('discussion', 'discussion must be a GitHub discussions URL');
|
||||
}
|
||||
}
|
||||
checkMaxLength('discussion', 300);
|
||||
|
||||
if (!missing.has('interactions')) {
|
||||
const interactions = entry.interactions;
|
||||
@@ -401,8 +473,12 @@ function renderMarkdown(entries, opts) {
|
||||
lines.push('| Name | What it is | Latest release | GSD compat | Discussion |');
|
||||
lines.push('|---|---|---|---|---|');
|
||||
for (const entry of sorted) {
|
||||
// entry.repo/enginesGsd/discussion are regex-constrained (validateEntries)
|
||||
// and used as link DESTINATIONS / badge URLs here — never mdInline those,
|
||||
// it would corrupt the URL. entry.name/description are untrusted free-text
|
||||
// link TEXT / body copy and MUST be escaped.
|
||||
lines.push(
|
||||
`| [${entry.name}](https://github.com/${entry.repo}) | ${entry.description} | ` +
|
||||
`| [${mdInline(entry.name)}](https://github.com/${entry.repo}) | ${mdInline(entry.description)} | ` +
|
||||
` | ` +
|
||||
`\`${entry.enginesGsd}\` | [discuss](${entry.discussion}) |`,
|
||||
);
|
||||
@@ -412,20 +488,25 @@ function renderMarkdown(entries, opts) {
|
||||
sorted.forEach((entry, i) => {
|
||||
const interactions = entry.interactions || {};
|
||||
|
||||
lines.push(`## ${entry.name}`);
|
||||
lines.push(`## ${mdInline(entry.name)}`);
|
||||
lines.push(
|
||||
`- **Repository:** https://github.com/${entry.repo} — [latest release](https://github.com/${entry.repo}/releases/latest)`,
|
||||
);
|
||||
lines.push(`- **What it is:** ${entry.description}`);
|
||||
lines.push(`- **What it is:** ${mdInline(entry.description)}`);
|
||||
lines.push(`- **Author:** ${mdInline(entry.author)}`);
|
||||
|
||||
if (isEos) {
|
||||
const axesSummary = Object.keys(AXES)
|
||||
.map((key) => `${key}=${interactions.axes ? interactions.axes[key] : undefined}`)
|
||||
.join(', ');
|
||||
lines.push(
|
||||
`- **Every interaction with GSD:** Interface points: ${(interactions.interfacePoints || []).join(', ')}; ` +
|
||||
`profile: ${interactions.profile}; protocol v${entry.protocolVersion}; axes: ${axesSummary}`,
|
||||
);
|
||||
const summary =
|
||||
`Interface points: ${(interactions.interfacePoints || []).join(', ')}; ` +
|
||||
`profile: ${interactions.profile}; protocol v${entry.protocolVersion}; axes: ${axesSummary}`;
|
||||
// Single mdInline pass over the fully-assembled summary: none of the
|
||||
// literal separator text above contains Markdown metacharacters, so
|
||||
// this equally neutralizes every embedded free-text/vocab value
|
||||
// (notably interactions.axes.dispatch, a free-form untrusted string).
|
||||
lines.push(`- **Every interaction with GSD:** ${mdInline(summary)}`);
|
||||
} else {
|
||||
let summary =
|
||||
`Loop Extension Points: ${(interactions.loopExtensionPoints || []).join(', ')}; ` +
|
||||
@@ -434,24 +515,33 @@ function renderMarkdown(entries, opts) {
|
||||
const v = interactions[field];
|
||||
if (Array.isArray(v) && v.length > 0) summary += `; ${field}: ${v.join(', ')}`;
|
||||
}
|
||||
lines.push(`- **Every interaction with GSD:** ${summary}`);
|
||||
// configKeys/requires/runtimeCompat/produces/consumes are untrusted
|
||||
// free-form strings (schema only requires "array of strings") — same
|
||||
// single-pass mdInline rationale as the eos branch above.
|
||||
lines.push(`- **Every interaction with GSD:** ${mdInline(summary)}`);
|
||||
}
|
||||
|
||||
// Code-span content (install/uninstall) is NOT mdInline-escaped — it is a
|
||||
// verbatim shell snippet, not inline prose. Instead each block picks a
|
||||
// fence strictly longer than any backtick run inside its own content, so
|
||||
// an embedded ``` cannot prematurely close the fence (CommonMark rule).
|
||||
const installFence = fenceFor(entry.install);
|
||||
lines.push('- **Install:**');
|
||||
lines.push('```sh');
|
||||
lines.push(`${installFence}sh`);
|
||||
lines.push(entry.install);
|
||||
lines.push('```');
|
||||
lines.push(installFence);
|
||||
const uninstallFence = fenceFor(entry.uninstall);
|
||||
lines.push('- **Uninstall:**');
|
||||
lines.push('```sh');
|
||||
lines.push(`${uninstallFence}sh`);
|
||||
lines.push(entry.uninstall);
|
||||
lines.push('```');
|
||||
lines.push(uninstallFence);
|
||||
|
||||
lines.push(
|
||||
isEos
|
||||
? `- **GSD compatibility:** \`${entry.enginesGsd}\`, protocol v${entry.protocolVersion}`
|
||||
: `- **GSD compatibility:** \`${entry.enginesGsd}\``,
|
||||
);
|
||||
lines.push(`- **License:** ${entry.license}`);
|
||||
lines.push(`- **License:** ${mdInline(entry.license)}`);
|
||||
lines.push(`- **Discussion / ranking:** ${entry.discussion}`);
|
||||
|
||||
if (i < sorted.length - 1) lines.push('');
|
||||
|
||||
@@ -102,6 +102,33 @@ describe('gen-registry CLI (subprocess)', () => {
|
||||
});
|
||||
});
|
||||
|
||||
describe('gen-registry CLI (subprocess): F3 — missing capabilities.json is an error, not a silent pass', () => {
|
||||
test('--check exits non-zero when docs/registries/ exists but capabilities.json is absent', () => {
|
||||
const tmp = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-gen-registry-nocaps-'));
|
||||
try {
|
||||
fs.mkdirSync(path.join(tmp, 'docs', 'registries'), { recursive: true });
|
||||
// Deliberately do NOT write capabilities.json — only eos.json is optional.
|
||||
const check = runGen(tmp, ['--check']);
|
||||
assert.notEqual(check.status, 0, `expected non-zero exit, got 0. stdout: ${check.stdout}`);
|
||||
assert.match(check.stderr, /capabilities\.json/);
|
||||
} finally {
|
||||
cleanup(tmp);
|
||||
}
|
||||
});
|
||||
|
||||
test('default mode (no flag) also hard-errors when capabilities.json is absent', () => {
|
||||
const tmp = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-gen-registry-nocaps-'));
|
||||
try {
|
||||
fs.mkdirSync(path.join(tmp, 'docs', 'registries'), { recursive: true });
|
||||
const result = runGen(tmp, []);
|
||||
assert.notEqual(result.status, 0, `expected non-zero exit, got 0. stdout: ${result.stdout}`);
|
||||
assert.match(result.stderr, /capabilities\.json/);
|
||||
} finally {
|
||||
cleanup(tmp);
|
||||
}
|
||||
});
|
||||
});
|
||||
|
||||
describe('gen-registry: renderMarkdown (direct, via registry-schema)', () => {
|
||||
test('renders empty-state text for an empty capability registry', () => {
|
||||
const rendered = renderMarkdown([], { type: 'capability', sourceFile: 'capabilities.json' });
|
||||
|
||||
@@ -339,6 +339,12 @@ describe('renderMarkdown', () => {
|
||||
assert.ok(rendered.includes(entry.discussion), 'expected rendered output to include the discussion URL');
|
||||
});
|
||||
|
||||
test('renders the author for a populated registry', () => {
|
||||
const entry = validCapabilityEntry();
|
||||
const rendered = renderMarkdown([entry], { type: 'capability', sourceFile: 'capabilities.json' });
|
||||
assert.match(rendered, /- \*\*Author:\*\* Octocat/);
|
||||
});
|
||||
|
||||
test('contains the empty-state text for zero entries', () => {
|
||||
const rendered = renderMarkdown([], { type: 'capability', sourceFile: 'capabilities.json' });
|
||||
assert.match(rendered, /No entries yet/);
|
||||
@@ -394,3 +400,230 @@ describe('isValidGsdRange', () => {
|
||||
}
|
||||
});
|
||||
});
|
||||
|
||||
// ─── renderMarkdown: Markdown-injection escaping (adversarial-review hardening) ──
|
||||
|
||||
describe('renderMarkdown: mdInline escaping neutralizes untrusted free text', () => {
|
||||
test('description containing a table-breakout + link-hijack payload is escaped', () => {
|
||||
const entry = validCapabilityEntry();
|
||||
entry.description = 'Good stuff |  | text';
|
||||
const rendered = renderMarkdown([entry], { type: 'capability', sourceFile: 'capabilities.json' });
|
||||
assert.ok(rendered.includes('\\|'), 'expected an escaped pipe (\\|) in the rendered output');
|
||||
assert.ok(
|
||||
!rendered.includes(''),
|
||||
'expected the raw unescaped link-hijack payload to NOT appear verbatim',
|
||||
);
|
||||
assert.ok(rendered.includes('\\['), 'expected an escaped [ (\\[), proving the hijack bracket was neutralized');
|
||||
});
|
||||
|
||||
test('name containing a link-hijack payload is escaped (no raw ](url) survives)', () => {
|
||||
const entry = validCapabilityEntry();
|
||||
entry.name = 'Evil] (https://evil.example) [';
|
||||
const rendered = renderMarkdown([entry], { type: 'capability', sourceFile: 'capabilities.json' });
|
||||
assert.ok(
|
||||
!rendered.includes('](https://evil.example)'),
|
||||
'expected the ] to be escaped, breaking the hijacked link destination pairing',
|
||||
);
|
||||
});
|
||||
|
||||
test('install containing an embedded ``` run gets a longer fence, keeping injected content inside the block', () => {
|
||||
const entry = validCapabilityEntry();
|
||||
entry.install = 'echo a\n```\n## FAKE\n```sh\nbad';
|
||||
const rendered = renderMarkdown([entry], { type: 'capability', sourceFile: 'capabilities.json' });
|
||||
|
||||
const openIdx = rendered.indexOf('````sh');
|
||||
assert.ok(openIdx !== -1, 'expected a 4-backtick opening fence (longer than the embedded 3-backtick run)');
|
||||
|
||||
const afterOpen = rendered.slice(openIdx + '````sh'.length);
|
||||
const closeIdx = afterOpen.indexOf('````');
|
||||
assert.ok(closeIdx !== -1, 'expected a matching 4-backtick closing fence');
|
||||
|
||||
const blockBody = afterOpen.slice(0, closeIdx);
|
||||
assert.ok(
|
||||
blockBody.includes('## FAKE'),
|
||||
'expected the injected "## FAKE" heading to remain INSIDE the fenced block, not escape it',
|
||||
);
|
||||
});
|
||||
|
||||
test('name/description with a raw newline: validateEntries rejects it, and if rendered anyway the newline collapses', () => {
|
||||
const nameEntry = validCapabilityEntry();
|
||||
nameEntry.name = 'Evil\nName';
|
||||
assert.equal(validateEntries([nameEntry], { type: 'capability' }).ok, false);
|
||||
|
||||
const descEntry = validCapabilityEntry();
|
||||
descEntry.description = 'Evil\nDescription';
|
||||
assert.equal(validateEntries([descEntry], { type: 'capability' }).ok, false);
|
||||
|
||||
// Defense in depth: renderMarkdown does not itself call validateEntries, so
|
||||
// confirm mdInline still collapses an embedded newline to a single space —
|
||||
// no raw newline lands inside a rendered table row.
|
||||
const rendered = renderMarkdown([nameEntry], { type: 'capability', sourceFile: 'capabilities.json' });
|
||||
const matchingRows = rendered.split('\n').filter((line) => line.startsWith('| [Evil'));
|
||||
assert.equal(matchingRows.length, 1, 'expected the newline-containing name to collapse into a single table row');
|
||||
assert.ok(matchingRows[0].includes('Evil Name'), `expected collapsed "Evil Name", got: ${matchingRows[0]}`);
|
||||
});
|
||||
});
|
||||
|
||||
// ─── validateEntries: null/non-object element guard (F2) ──────────────────────
|
||||
|
||||
describe('validateEntries: null/non-object element guard (F2)', () => {
|
||||
test('a null entry fails without throwing', () => {
|
||||
let verdict;
|
||||
assert.doesNotThrow(() => {
|
||||
verdict = validateEntries([null], { type: 'capability' });
|
||||
});
|
||||
assert.equal(verdict.ok, false);
|
||||
assert.ok(verdict.errors.some((e) => e.field === '(entry)'));
|
||||
});
|
||||
|
||||
test('an undefined entry fails without throwing', () => {
|
||||
let verdict;
|
||||
assert.doesNotThrow(() => {
|
||||
verdict = validateEntries([undefined], { type: 'capability' });
|
||||
});
|
||||
assert.equal(verdict.ok, false);
|
||||
assert.ok(verdict.errors.some((e) => e.field === '(entry)'));
|
||||
});
|
||||
|
||||
test('primitive and array elements fail without throwing', () => {
|
||||
const verdict = validateEntries(['a string', [1, 2, 3], 42], { type: 'capability' });
|
||||
assert.equal(verdict.ok, false);
|
||||
assert.equal(verdict.errors.filter((e) => e.field === '(entry)').length, 3);
|
||||
});
|
||||
});
|
||||
|
||||
// ─── renderMarkdown: eos registry (F4) ─────────────────────────────────────────
|
||||
|
||||
describe('renderMarkdown: eos registry (F4)', () => {
|
||||
test('renders the eos heading, the free-form dispatch text, protocol wording, and integration wording', () => {
|
||||
const rendered = renderMarkdown([validEosEntry()], { type: 'eos', sourceFile: 'eos.json' });
|
||||
assert.match(rendered, /# GSD EoS Registry/);
|
||||
assert.ok(rendered.includes('Supports nested background dispatch up to depth 3.'));
|
||||
assert.match(rendered, /protocol v1/);
|
||||
assert.match(rendered, /integration/);
|
||||
});
|
||||
});
|
||||
|
||||
// ─── validateEntries: interactions guards (F4) ─────────────────────────────────
|
||||
|
||||
describe('validateEntries: interactions guards (F4)', () => {
|
||||
test('capability interactions.someUnknownKey fails at the qualified field', () => {
|
||||
const entry = validCapabilityEntry();
|
||||
entry.interactions.someUnknownKey = 'x';
|
||||
const verdict = validateEntries([entry], { type: 'capability' });
|
||||
assert.equal(verdict.ok, false);
|
||||
assert.ok(verdict.errors.some((e) => e.field === 'interactions.someUnknownKey'));
|
||||
});
|
||||
|
||||
test('eos interactions.someUnknownKey fails at the qualified field', () => {
|
||||
const entry = validEosEntry();
|
||||
entry.interactions.someUnknownKey = 'x';
|
||||
const verdict = validateEntries([entry], { type: 'eos' });
|
||||
assert.equal(verdict.ok, false);
|
||||
assert.ok(verdict.errors.some((e) => e.field === 'interactions.someUnknownKey'));
|
||||
});
|
||||
|
||||
test('interactions.configKeys as a non-array string fails', () => {
|
||||
const entry = validCapabilityEntry();
|
||||
entry.interactions.configKeys = 'nope';
|
||||
const verdict = validateEntries([entry], { type: 'capability' });
|
||||
assert.equal(verdict.ok, false);
|
||||
assert.ok(verdict.errors.some((e) => e.field === 'interactions.configKeys'));
|
||||
});
|
||||
|
||||
test('interactions.configKeys with non-string elements fails', () => {
|
||||
const entry = validCapabilityEntry();
|
||||
entry.interactions.configKeys = [123];
|
||||
const verdict = validateEntries([entry], { type: 'capability' });
|
||||
assert.equal(verdict.ok, false);
|
||||
assert.ok(verdict.errors.some((e) => e.field === 'interactions.configKeys'));
|
||||
});
|
||||
|
||||
test('eos interactions.axes as a non-object string fails', () => {
|
||||
const entry = validEosEntry();
|
||||
entry.interactions.axes = 'nope';
|
||||
const verdict = validateEntries([entry], { type: 'eos' });
|
||||
assert.equal(verdict.ok, false);
|
||||
assert.ok(verdict.errors.some((e) => e.field === 'interactions.axes'));
|
||||
});
|
||||
});
|
||||
|
||||
// ─── validateEntries: new hardening checks (length caps, tightened regexes) ────
|
||||
|
||||
describe('validateEntries: description length cap (max 1000)', () => {
|
||||
test('999 chars (limit-1) passes the cap', () => {
|
||||
const entry = validCapabilityEntry();
|
||||
entry.description = 'x'.repeat(999);
|
||||
const verdict = validateEntries([entry], { type: 'capability' });
|
||||
assert.ok(!verdict.errors.some((e) => e.field === 'description' && /exceeds max length/.test(e.reason)));
|
||||
});
|
||||
|
||||
test('1000 chars (limit) passes the cap', () => {
|
||||
const entry = validCapabilityEntry();
|
||||
entry.description = 'x'.repeat(1000);
|
||||
const verdict = validateEntries([entry], { type: 'capability' });
|
||||
assert.ok(!verdict.errors.some((e) => e.field === 'description' && /exceeds max length/.test(e.reason)));
|
||||
});
|
||||
|
||||
test('1001 chars (limit+1) fails the cap', () => {
|
||||
const entry = validCapabilityEntry();
|
||||
entry.description = 'x'.repeat(1001);
|
||||
const verdict = validateEntries([entry], { type: 'capability' });
|
||||
assert.equal(verdict.ok, false);
|
||||
assert.ok(verdict.errors.some((e) => e.field === 'description' && /exceeds max length 1000/.test(e.reason)));
|
||||
});
|
||||
});
|
||||
|
||||
describe('validateEntries: entry-count cap (max 2000)', () => {
|
||||
function makeEntries(n) {
|
||||
return Array.from({ length: n }, (_, i) => ({
|
||||
...validCapabilityEntry(),
|
||||
id: `cap-${i}`,
|
||||
repo: `octocat/cap-${i}`,
|
||||
discussion: `https://github.com/octocat/cap-${i}/discussions/1`,
|
||||
}));
|
||||
}
|
||||
|
||||
test('1999 entries (limit-1) does not trip the cap', () => {
|
||||
const verdict = validateEntries(makeEntries(1999), { type: 'capability' });
|
||||
assert.ok(!verdict.errors.some((e) => e.field === '(root)'));
|
||||
});
|
||||
|
||||
test('2000 entries (limit) does not trip the cap', () => {
|
||||
const verdict = validateEntries(makeEntries(2000), { type: 'capability' });
|
||||
assert.ok(!verdict.errors.some((e) => e.field === '(root)'));
|
||||
});
|
||||
|
||||
test('2001 entries (limit+1) trips the cap with a single root error', () => {
|
||||
const verdict = validateEntries(makeEntries(2001), { type: 'capability' });
|
||||
assert.equal(verdict.ok, false);
|
||||
assert.equal(verdict.errors.length, 1);
|
||||
assert.equal(verdict.errors[0].field, '(root)');
|
||||
assert.match(verdict.errors[0].reason, /max 2000/);
|
||||
});
|
||||
});
|
||||
|
||||
describe('validateEntries: tightened discussion/license regexes', () => {
|
||||
test('discussion URL containing an injection char ([) fails the tightened regex', () => {
|
||||
const entry = validCapabilityEntry();
|
||||
entry.discussion = 'https://github.com/a[b/c/discussions/1';
|
||||
const verdict = validateEntries([entry], { type: 'capability' });
|
||||
assert.equal(verdict.ok, false);
|
||||
assert.ok(verdict.errors.some((e) => e.field === 'discussion'));
|
||||
});
|
||||
|
||||
test('license containing a newline fails the tightened regex', () => {
|
||||
const entry = validCapabilityEntry();
|
||||
entry.license = 'MIT\nEVIL';
|
||||
const verdict = validateEntries([entry], { type: 'capability' });
|
||||
assert.equal(verdict.ok, false);
|
||||
assert.ok(verdict.errors.some((e) => e.field === 'license'));
|
||||
});
|
||||
|
||||
test('a compound SPDX license ("MIT OR Apache-2.0") still passes', () => {
|
||||
const entry = validCapabilityEntry();
|
||||
entry.license = 'MIT OR Apache-2.0';
|
||||
const verdict = validateEntries([entry], { type: 'capability' });
|
||||
assert.ok(!verdict.errors.some((e) => e.field === 'license'));
|
||||
});
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user