fix(02): reject trailing JSON after the first decoded value (WR-03)

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Jakub Zych
2026-09-17 14:41:59 +02:00
parent 5cb2defe0f
commit d3d202e0e2
2 changed files with 18 additions and 0 deletions

View File

@@ -130,6 +130,9 @@ func decodeJSON(raw []byte) (any, error) {
if err := dec.Decode(&v); err != nil {
return nil, err
}
if dec.More() {
return nil, fmt.Errorf("trailing JSON after first value")
}
return v, nil
}

View File

@@ -32,3 +32,18 @@ func TestDiffParityClasses(t *testing.T) {
check("conditional key", `{"data":{"name":"a"}}`, `{"data":{"name":"a","extra":1}}`, "extra")
check("date vs Z", `{"created_at":"2026-01-01T00:00:00+00:00"}`, `{"created_at":"2026-01-01T00:00:00Z"}`, "created_at")
}
func TestDecodeJSONRejectsTrailingValue(t *testing.T) {
if _, err := decodeJSON([]byte(`{"data":[]}`)); err != nil {
t.Fatalf("single value: %v", err)
}
if _, err := decodeJSON([]byte(`{"data":[]}{"debug":true}`)); err == nil || !strings.Contains(err.Error(), "trailing JSON") {
t.Fatalf("trailing value: %v", err)
}
want := Response{Headers: jsonCT(), Body: Body(`{"data":[]}{"debug":true}`)}
got := Response{Headers: jsonCT(), Body: Body(`{"data":[]}`)}
diffs := compareBodies(want, got, Step{ID: "trail"})
if len(diffs) == 0 {
t.Fatal("trailing JSON envelope must mismatch")
}
}