test: complete regex-escape class in worktree-safety assertion (#1589)
CodeQL alert #41 (js/incomplete-sanitization) flagged the partial escape class /[-]/g at tests/worktree-safety.test.cjs:645 — it only escaped hyphen-minus, leaving 13 other regex metacharacters (notably backslash) unescaped. The canonical class /[.*+?^${}()|[\]\\]/g is what every sibling escape in the test suite already uses (bug-2839, bug-2760, 4-phase-complete, phase6-capstone-conformance). Today dormant: the flag array is a hardcoded [a-z-] literal, so the expanded class is a no-op for the four existing flags and the regexes they produce are byte-identical. The fix prevents future drift — a contributor adding e.g. '--output=file' would have silently introduced a regex wildcard. All 69 tests in the file pass. No user-facing behavior change. Fixes #1589
This commit is contained in:
@@ -642,7 +642,7 @@ describe('planWorktreeRecordAgent', () => {
|
||||
});
|
||||
assert.equal(plan.reason, 'missing_field');
|
||||
for (const flag of ['--agent-id', '--path', '--branch', '--base']) {
|
||||
assert.match(plan.hint, new RegExp(flag.replace(/[-]/g, '\\$&')));
|
||||
assert.match(plan.hint, new RegExp(flag.replace(/[.*+?^${}()|[\]\\]/g, '\\$&')));
|
||||
}
|
||||
});
|
||||
|
||||
|
||||
Reference in New Issue
Block a user