* feat(#2982): extend no-source-grep lint to catch var-binding readFileSync.includes() The base lint (scripts/lint-no-source-grep.cjs) only catches readFileSync(...).<text-method>() chained directly. The much more common var-binding form escapes it: const src = fs.readFileSync(p, 'utf8'); // 50 lines later if (src.includes('foo')) {} // ← still grep, lint missed it Scan of the test suite found ~141 files using this pattern. Implementation built TDD per #2982 with structured-IR assertions: scripts/lint-no-source-grep-extras.cjs - detectVarBindingViolations(src) — pure detector, two passes: pass 1 collects vars bound from readFileSync, pass 2 finds any <var>.<includes|startsWith|endsWith|match|search>( on those vars. - detectWrappedAssertOkMatch(src) — flags assert.ok(<expr>.match(...)) which escapes the assert.match rule. - VIOLATION enum exposes stable codes for tests to assert on. scripts/lint-no-source-grep.cjs - Wires the new detectors into the existing per-file check; one additional violation row per file with the first 3 sample tokens. tests/bug-2982-lint-var-binding.test.cjs - 13 tests, all assertions on typed VIOLATION enum / structured records. Covers all 5 text-match methods, multi-var, no-bind, string literal (must NOT trigger), wrapped assert.ok(.match), and assert.match (must NOT double-flag). Migration backlog (#2974 expanded scope): - 42 files annotated `// allow-test-rule: source-text-is-the-product` (legitimate — they read .md/.json/.yml files whose deployed text IS the product) - 3 files annotated `// allow-test-rule: pending-migration-to-typed-ir [#2974]` (read .cjs/.js source — clear migration debt) - 95 files annotated `pending-migration-to-typed-ir [#2974]` with `Per-file review may reclassify as source-text-is-the-product during migration` (mixed — manual review under #2974) After this lands the lint reports 0 violations on main; new violations in PRs surface immediately. Closes #2982 Refs #2974 * test(#2982): fix truncated test name per CR The label ended with a bare '(' from a copy-paste mishap. Now reads 'does NOT flag .matchAll(...) — matchAll is not match, so assert.ok(.matchAll(...)) is not flagged'. * chore(#2982): add changeset fragment for PR #2985 * chore(#2982): add changeset fragment for PR #2985
110 lines
3.3 KiB
JavaScript
110 lines
3.3 KiB
JavaScript
'use strict';
|
|
|
|
// allow-test-rule: source-text-is-the-product
|
|
// Reads .md/.json/.yml product files whose deployed text IS what the
|
|
// runtime loads — testing text content tests the deployed contract.
|
|
|
|
const { describe, test } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const fs = require('fs');
|
|
const path = require('path');
|
|
|
|
describe('thread session management (#2156)', () => {
|
|
const threadCmd = fs.readFileSync(
|
|
path.join(__dirname, '..', 'commands', 'gsd', 'thread.md'),
|
|
'utf8'
|
|
);
|
|
|
|
test('thread command has list subcommand with status filter', () => {
|
|
assert.ok(
|
|
threadCmd.includes('list --open') || threadCmd.includes('LIST-OPEN'),
|
|
'missing list --open filter'
|
|
);
|
|
});
|
|
|
|
test('thread command has close subcommand', () => {
|
|
assert.ok(
|
|
threadCmd.includes('CLOSE') || threadCmd.includes('close <slug>'),
|
|
'missing close subcommand'
|
|
);
|
|
});
|
|
|
|
test('thread command has status subcommand', () => {
|
|
assert.ok(
|
|
threadCmd.includes('STATUS') || threadCmd.includes('status <slug>'),
|
|
'missing status subcommand'
|
|
);
|
|
});
|
|
|
|
test('thread command does not use heredoc', () => {
|
|
assert.ok(
|
|
!threadCmd.includes("<< 'EOF'") && !threadCmd.includes('<< EOF'),
|
|
'thread command still uses heredoc — injection risk'
|
|
);
|
|
});
|
|
|
|
test('thread template includes frontmatter status field', () => {
|
|
assert.ok(
|
|
threadCmd.includes('status: open') || threadCmd.includes('status:'),
|
|
'thread template missing frontmatter status field'
|
|
);
|
|
});
|
|
|
|
test('thread command has security_notes section', () => {
|
|
assert.ok(threadCmd.includes('security_notes'), 'missing security_notes section');
|
|
});
|
|
|
|
test('thread command has slug sanitization', () => {
|
|
assert.ok(
|
|
threadCmd.includes('sanitiz') || threadCmd.includes('[a-z0-9'),
|
|
'missing slug sanitization'
|
|
);
|
|
});
|
|
|
|
test('thread command uses Write tool for file creation', () => {
|
|
assert.ok(
|
|
threadCmd.includes('Write tool'),
|
|
'thread create mode should use the Write tool instead of heredoc'
|
|
);
|
|
});
|
|
|
|
test('thread command list reads frontmatter status', () => {
|
|
assert.ok(
|
|
threadCmd.includes('frontmatter get') || threadCmd.includes('frontmatter.get'),
|
|
'list mode should read status via frontmatter get / frontmatter.get'
|
|
);
|
|
});
|
|
|
|
test('thread command close updates status to resolved', () => {
|
|
assert.ok(
|
|
threadCmd.includes('resolved'),
|
|
'close mode should set status to resolved'
|
|
);
|
|
});
|
|
|
|
test('thread command list shows resolved filter option', () => {
|
|
assert.ok(
|
|
threadCmd.includes('list --resolved') || threadCmd.includes('LIST-RESOLVED'),
|
|
'missing list --resolved filter'
|
|
);
|
|
});
|
|
|
|
test('thread command rejects slugs with path traversal', () => {
|
|
assert.ok(
|
|
threadCmd.includes('..') && threadCmd.includes('reject'),
|
|
'missing path traversal rejection for slugs'
|
|
);
|
|
});
|
|
|
|
test('thread create uses frontmatter with slug title status created updated fields', () => {
|
|
assert.ok(
|
|
threadCmd.includes('slug:') &&
|
|
threadCmd.includes('title:') &&
|
|
threadCmd.includes('status:') &&
|
|
threadCmd.includes('created:') &&
|
|
threadCmd.includes('updated:'),
|
|
'thread template missing required frontmatter fields'
|
|
);
|
|
});
|
|
});
|