Skip to content

fix(storefront): validate all optional data consumed by rendering - #60

Merged
Xuepoo merged 1 commit into
mainfrom
carryctx/ctx-0028
Sep 26, 2026
Merged

Xuepoo merged 1 commit into
mainfrom
carryctx/ctx-0028

Conversation

@Xuepoo

@Xuepoo Xuepoo commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

Closes #49

Priority: P2 | Area: ui | Labels: fix, P2, area:ui | Milestone: v0.1.0 | RFC: not identified | Task: CTX-0028

Summary

Extends isPlugin() to validate all optional registry fields consumed by UI rendering before accepting registry.json. Prevents invalid shapes from aborting rendering or search per PLUG-REG-002.

Changes

  • app/src/registry.ts: Add validation helpers and extend isPlugin()

    • isStringArray(): validates string arrays (tags, categories)
    • isCompatibility(): validates compatibility object and nested fields
    • isPluginMetadata(): validates metadata object and nested fields
    • Extended isPlugin() to validate all optional fields: author, description, license, tags, categories, compatibility, manifest_hash, metadata
  • tests/storefront-validation.test.ts: Comprehensive test coverage (159 tests)

    • Valid optional field shapes (strings, arrays, objects)
    • Invalid type rejection (non-strings, non-arrays, mixed types)
    • Edge cases (empty arrays/objects, null, undefined)
    • Graceful degradation scenarios for rendering/search

Validation Coverage

All optional fields consumed by rendering are now validated:

  • plugin-card.ts:75-82: tags, metadata.version, license
  • plugin-detail.ts:22-24, 72-107: author, categories, tags, license, compatibility.bitty/sdk, metadata.version
  • search.ts:43-52: author, categories, tags, description
  • registry.ts:146-150: categories array iteration

Quality Gates

All checks pass:

  • ✅ Format (prettier)
  • ✅ Lint (markdownlint)
  • ✅ Type check (TypeScript)
  • ✅ Tests (159 pass, 0 fail)
  • ✅ Registry validation
  • ✅ Build (app)

Security

Registry data remains untrusted input. Validation prevents malformed optional fields from causing rendering crashes or search failures. Text-only rendering safeguards (textContent, no innerHTML) remain intact.

Extends isPlugin() to validate all optional registry fields consumed
by UI rendering (author, description, license, tags, categories,
compatibility, manifest_hash, metadata) before accepting registry.json.

- Add isStringArray(), isCompatibility(), isPluginMetadata() helpers
- Validate optional string fields (author, description, license)
- Validate optional array fields (tags, categories) and their elements
- Validate optional object fields (compatibility, metadata) and nested fields
- Add 159 comprehensive tests in storefront-validation.test.ts covering:
  - Valid optional field shapes (strings, arrays, objects)
  - Invalid type rejection (non-strings, non-arrays, mixed types)
  - Edge cases (empty arrays/objects, null, undefined)
  - Graceful degradation scenarios for rendering/search

Prevents invalid shapes from aborting rendering or search per PLUG-REG-002.
All quality gates pass (format, lint, type-check, tests, registry validation).

Closes #49
@Xuepoo Xuepoo added this to the v0.1.0 milestone Sep 26, 2026
@Xuepoo Xuepoo added fix Bug fix area:ui Area: UI / layout P2 Priority: medium labels Sep 26, 2026
@Xuepoo
Xuepoo merged commit 73fe400 into main Sep 26, 2026
6 checks passed
@Xuepoo
Xuepoo deleted the carryctx/ctx-0028 branch September 26, 2026 06:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:ui Area: UI / layout fix Bug fix P2 Priority: medium

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant