Guard add_word_list against reserved dictionary names#118
Merged
Conversation
`add_word_list("passwords", …)` silently replaced the 30k built-in list;
`add_word_list("user_inputs", …)` created a permanent dictionary
indistinguishable from per-call user inputs. Both now raise `ArgumentError`.
a989f60 to
ea0acc9
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Context
TesterBuilder#add_word_listaccepts any name. Passing a built-in dictionary name (e.g."passwords") silently replaces the 30k built-in list with whatever the caller supplies. Passing"user_inputs"creates a permanent dictionary that is indistinguishable from per-call user inputs when filtering onmatch.dictionary_name.Changes
Data::RESERVED_NAMES— the six built-in dictionary names plus"user_inputs".add_word_listraisesArgumentErrorwhen the name is in that set.Consequences
Callers using a reserved name get an immediate, descriptive error rather than silent misbehaviour. Any caller intentionally passing a built-in name to replace it will need to use a different name — this is a new API introduced in this release, so there is no backwards-compatibility concern.