fix(notify): classify npm alias notify specs as unsafe
This commit is contained in:
@@ -137,6 +137,35 @@ describe("ensureBundledNotifyOwnership", () => {
|
|||||||
expect(readConfig(userConfigPath).plugin).toEqual([["npm:@custom/opencode-notify@1.2.3", {}], "oh-my-openagent"])
|
expect(readConfig(userConfigPath).plugin).toEqual([["npm:@custom/opencode-notify@1.2.3", {}], "oh-my-openagent"])
|
||||||
})
|
})
|
||||||
|
|
||||||
|
test("fails loudly for npm alias string spec targeting custom opencode-notify package", () => {
|
||||||
|
// given
|
||||||
|
const userConfigPath = join(userConfigDir, "opencode.json")
|
||||||
|
writeFileSync(userConfigPath, JSON.stringify({ plugin: ["alias@npm:@custom/opencode-notify@1.2.3", "oh-my-openagent"] }, null, 2) + "\n")
|
||||||
|
|
||||||
|
// when
|
||||||
|
const run = () => ensureBundledNotifyOwnership({ projectDirectory: projectDir, packageRoot })
|
||||||
|
|
||||||
|
// then
|
||||||
|
expect(run).toThrow("Unsafe external notify plugin ownership detected")
|
||||||
|
expect(readConfig(userConfigPath).plugin).toEqual(["alias@npm:@custom/opencode-notify@1.2.3", "oh-my-openagent"])
|
||||||
|
})
|
||||||
|
|
||||||
|
test("fails loudly for npm alias tuple spec targeting custom opencode-notify package", () => {
|
||||||
|
// given
|
||||||
|
const userConfigPath = join(userConfigDir, "opencode.json")
|
||||||
|
writeFileSync(
|
||||||
|
userConfigPath,
|
||||||
|
JSON.stringify({ plugin: [["alias@npm:@custom/opencode-notify@1.2.3", {}], "oh-my-openagent"] }, null, 2) + "\n",
|
||||||
|
)
|
||||||
|
|
||||||
|
// when
|
||||||
|
const run = () => ensureBundledNotifyOwnership({ projectDirectory: projectDir, packageRoot })
|
||||||
|
|
||||||
|
// then
|
||||||
|
expect(run).toThrow("Unsafe external notify plugin ownership detected")
|
||||||
|
expect(readConfig(userConfigPath).plugin).toEqual([["alias@npm:@custom/opencode-notify@1.2.3", {}], "oh-my-openagent"])
|
||||||
|
})
|
||||||
|
|
||||||
test("migrates stale bundled dist/opencode-notify file URL to canonical bundled entry", () => {
|
test("migrates stale bundled dist/opencode-notify file URL to canonical bundled entry", () => {
|
||||||
// given
|
// given
|
||||||
const userConfigPath = join(userConfigDir, "opencode.json")
|
const userConfigPath = join(userConfigDir, "opencode.json")
|
||||||
|
|||||||
@@ -83,12 +83,23 @@ function stripVersionSuffix(entry: string): string {
|
|||||||
return trimmed.slice(0, versionSeparatorIndex)
|
return trimmed.slice(0, versionSeparatorIndex)
|
||||||
}
|
}
|
||||||
|
|
||||||
function isCustomPackageNotifyCandidate(entry: string): boolean {
|
function extractPackageIdentifierFromSpec(entry: string): string | null {
|
||||||
const normalized = stripNpmPrefix(entry.trim().toLowerCase())
|
const normalized = stripNpmPrefix(entry.trim().toLowerCase())
|
||||||
if (normalized.length === 0) return false
|
if (normalized.length === 0) return null
|
||||||
if (normalized.includes("://")) return false
|
if (normalized.includes("://")) return null
|
||||||
|
|
||||||
const packageIdentifier = stripVersionSuffix(normalized)
|
const aliasSeparatorIndex = normalized.indexOf("@npm:")
|
||||||
|
const packageSpec = aliasSeparatorIndex >= 0
|
||||||
|
? normalized.slice(aliasSeparatorIndex + "@npm:".length)
|
||||||
|
: normalized
|
||||||
|
|
||||||
|
if (packageSpec.length === 0) return null
|
||||||
|
return stripVersionSuffix(packageSpec)
|
||||||
|
}
|
||||||
|
|
||||||
|
function isCustomPackageNotifyCandidate(entry: string): boolean {
|
||||||
|
const packageIdentifier = extractPackageIdentifierFromSpec(entry)
|
||||||
|
if (!packageIdentifier) return false
|
||||||
if (packageIdentifier === "opencode-notify") return true
|
if (packageIdentifier === "opencode-notify") return true
|
||||||
if (/^@[a-z0-9._-]+\/opencode-notify$/i.test(packageIdentifier)) return true
|
if (/^@[a-z0-9._-]+\/opencode-notify$/i.test(packageIdentifier)) return true
|
||||||
if (/^[a-z0-9._-]+\/opencode-notify$/i.test(packageIdentifier)) return true
|
if (/^[a-z0-9._-]+\/opencode-notify$/i.test(packageIdentifier)) return true
|
||||||
|
|||||||
Reference in New Issue
Block a user