fix(storefront): validate all optional data consumed by rendering - #60
Merged
Merged
Conversation
Extends isPlugin() to validate all optional registry fields consumed by UI rendering (author, description, license, tags, categories, compatibility, manifest_hash, metadata) before accepting registry.json. - Add isStringArray(), isCompatibility(), isPluginMetadata() helpers - Validate optional string fields (author, description, license) - Validate optional array fields (tags, categories) and their elements - Validate optional object fields (compatibility, metadata) and nested fields - Add 159 comprehensive tests in storefront-validation.test.ts covering: - Valid optional field shapes (strings, arrays, objects) - Invalid type rejection (non-strings, non-arrays, mixed types) - Edge cases (empty arrays/objects, null, undefined) - Graceful degradation scenarios for rendering/search Prevents invalid shapes from aborting rendering or search per PLUG-REG-002. All quality gates pass (format, lint, type-check, tests, registry validation). Closes #49
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #49
Priority: P2 | Area: ui | Labels: fix, P2, area:ui | Milestone: v0.1.0 | RFC: not identified | Task: CTX-0028
Summary
Extends
isPlugin()to validate all optional registry fields consumed by UI rendering before acceptingregistry.json. Prevents invalid shapes from aborting rendering or search per PLUG-REG-002.Changes
app/src/registry.ts: Add validation helpers and extend
isPlugin()isStringArray(): validates string arrays (tags, categories)isCompatibility(): validates compatibility object and nested fieldsisPluginMetadata(): validates metadata object and nested fieldsisPlugin()to validate all optional fields: author, description, license, tags, categories, compatibility, manifest_hash, metadatatests/storefront-validation.test.ts: Comprehensive test coverage (159 tests)
Validation Coverage
All optional fields consumed by rendering are now validated:
tags,metadata.version,licenseauthor,categories,tags,license,compatibility.bitty/sdk,metadata.versionauthor,categories,tags,descriptioncategoriesarray iterationQuality Gates
All checks pass:
Security
Registry data remains untrusted input. Validation prevents malformed optional fields from causing rendering crashes or search failures. Text-only rendering safeguards (textContent, no innerHTML) remain intact.