fix: add input validation and safe JSON parsing across 13 CLIs

Add missing parameter validation to prevent /path/undefined API calls:
- dub: require --url for links create
- google-search-console: require --sitemap-url for sitemaps submit
- kit: validate IDs and emails for subscribers, forms, sequences, tags, broadcasts
- mailchimp: validate IDs for lists get, campaigns get/create/send, members add, reports get
- resend: validate --from/--to/--subject for send, audience/contact IDs for contacts
- rewardful: validate IDs for affiliates get/update, commissions get, links create
- semrush: require --domain/--phrase for all domain and keyword commands
- sendgrid: validate --from/--to/--subject for send, campaign IDs, email for validate

Wrap bare JSON.parse() calls in try/catch for user-provided JSON:
- dub (--links), ga4 (--params), kit (--fields x4), mixpanel (--properties x2),
  onesignal (--filters), paddle (--scheduled-change, --items x2),
  resend (--emails, --variables x2), segment (--properties, --traits, --events),
  sendgrid (--template-data)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Corey Haines
2026-02-17 22:44:06 -08:00
parent 51bdf2f6b3
commit 8eaff5e29f
13 changed files with 103 additions and 20 deletions
+7
View File
@@ -69,6 +69,7 @@ async function main() {
break
}
case 'get':
if (!rest[0]) { result = { error: 'List ID required' }; break }
result = await api('GET', `/lists/${rest[0]}`)
break
default:
@@ -91,6 +92,8 @@ async function main() {
break
}
case 'add': {
if (!rest[0]) { result = { error: 'List ID required' }; break }
if (!args.email) { result = { error: '--email required' }; break }
if (!args['list-id']) {
result = { error: '--list-id is required for members add' }
break
@@ -142,9 +145,11 @@ async function main() {
break
}
case 'get':
if (!rest[0]) { result = { error: 'Campaign ID required' }; break }
result = await api('GET', `/campaigns/${rest[0]}`)
break
case 'create': {
if (!args['list-id']) { result = { error: '--list-id required' }; break }
const body = {
type: args.type || 'regular',
recipients: {
@@ -160,6 +165,7 @@ async function main() {
break
}
case 'send':
if (!rest[0]) { result = { error: 'Campaign ID required' }; break }
result = await api('POST', `/campaigns/${rest[0]}/actions/send`)
break
default:
@@ -170,6 +176,7 @@ async function main() {
case 'reports':
switch (sub) {
case 'get':
if (!rest[0]) { result = { error: 'Campaign ID required' }; break }
result = await api('GET', `/reports/${rest[0]}`)
break
default: