e5d3fe96c4
Blocking fixes: - B1: Return empty restrictions for unknown/custom agents instead of EXPLORATION_AGENT_DENYLIST, allowing custom agents full tool access - B2: Use Object.create(null) consistently across all 5 agent-loading result objects to prevent prototype pollution - B3: Add code comment documenting custom agent bash access trust model - B4: Mock getOpenCodeConfigDir in opencode-config-agents-reader tests to prevent global config dir leakage Non-blocking fixes: - N1: Use resolveAgentDefinitionPaths with project boundary enforcement in opencode-config-agents-reader for path containment - N2: Add session-scoped 30s TTL cache to resolveCallableAgents to avoid redundant SDK IPC calls per tool invocation - N3: Extract shared parseToolsConfig into src/shared/parse-tools-config.ts replacing 4 duplicated local implementations - N4: Add .min(1) to AgentDefinitionPathSchema rejecting empty paths - N5: Add resolve-agent-definition-paths.test.ts covering tilde expansion, relative paths, boundary enforcement, and null containmentDir - N6: Validate agent mode against allowed values instead of bare type assertion in opencode-config-agents-reader
26 lines
847 B
TypeScript
26 lines
847 B
TypeScript
/**
|
|
* Parses a tools configuration value into a boolean record.
|
|
* Accepts comma-separated strings, string arrays, or unknown values from config files.
|
|
* Returns undefined when input is empty or invalid.
|
|
*/
|
|
export function parseToolsConfig(toolsValue: unknown): Record<string, boolean> | undefined {
|
|
if (!toolsValue) return undefined
|
|
|
|
let items: string[]
|
|
if (typeof toolsValue === "string") {
|
|
items = toolsValue.split(",").map((t) => t.trim()).filter(Boolean)
|
|
} else if (Array.isArray(toolsValue)) {
|
|
items = toolsValue.filter((t) => typeof t === "string" && t.trim().length > 0).map((t) => (t as string).trim())
|
|
} else {
|
|
return undefined
|
|
}
|
|
|
|
if (items.length === 0) return undefined
|
|
|
|
const result: Record<string, boolean> = {}
|
|
for (const tool of items) {
|
|
result[tool.toLowerCase()] = true
|
|
}
|
|
return result
|
|
}
|