Reject unsafe Eidos CSS config values

active-uix
dev 5 months ago
parent 546ad40251
commit b2c832b47a

@ -40,10 +40,12 @@ Actualizacion Eidos ecosystem 2026-05-16:
de theme. de theme.
- Overrides de `semantics.color.roles.*.slots` quedan validados: solo slots - Overrides de `semantics.color.roles.*.slots` quedan validados: solo slots
canonicos y pasos `1..12`. canonicos y pasos `1..12`.
- Valores CSS del `EidosConfig` comparten la misma defensa que los overrides
runtime: no pueden contener `;`, `{` ni `}`.
- Validado: - Validado:
- `npx vitest run src/uix/eidos/active-eidos-config.test.ts` -> 33 tests OK. - `npx vitest run src/uix/eidos/active-eidos-config.test.ts` -> 34 tests OK.
- `npx vitest run src/uix/eidos/active-eidos.test.ts` -> 19 tests OK. - `npx vitest run src/uix/eidos/active-eidos.test.ts` -> 19 tests OK.
- `npx vitest run src/uix/eidos` -> 7 archivos, 73 tests OK. - `npx vitest run src/uix/eidos` -> 7 archivos, 74 tests OK.
- `npm run check` -> 0 errores, 0 warnings. - `npm run check` -> 0 errores, 0 warnings.
Actualizacion permutation runner 2026-05-16: Actualizacion permutation runner 2026-05-16:

@ -558,6 +558,23 @@ describe('ActiveEidos config', () => {
expect(report.issues.some((issue) => issue.path === 'recipes.tooltip.empty-token')).toBe(true) expect(report.issues.some((issue) => issue.path === 'recipes.tooltip.empty-token')).toBe(true)
}) })
it('rejects config CSS values that contain declaration delimiters', () => {
const cfg = structuredClone(THEME_BASE_OPTIONS)
;(cfg.recipes!.tooltip as Record<string, string>)['content-bg'] =
'red; color: transparent'
;(cfg.themes!['base-light'].color!.surface as unknown as Record<string, string>).default =
'Canvas { color: red }'
const report = createEidos(cfg).validate()
expect(report.ok).toBe(false)
expect(report.issues.some((issue) => issue.path === 'recipes.tooltip.content-bg')).toBe(true)
expect(
report.issues.some((issue) => issue.path === 'themes.base-light.color.surface.default')
).toBe(true)
})
it('validates role mappings against every configured theme', () => { it('validates role mappings against every configured theme', () => {
const cfg: EidosConfig = { const cfg: EidosConfig = {
...THEME_BASE_OPTIONS, ...THEME_BASE_OPTIONS,

@ -413,7 +413,9 @@ function validateColorSemanticGroup(
path: `${path}.${key}`, path: `${path}.${key}`,
message: 'color semantic CSS value cannot be empty' message: 'color semantic CSS value cannot be empty'
}) })
continue
} }
validateNonEmptyCssValue(`${path}.${key}`, value, issues)
} }
for (const key of Object.keys(group)) { for (const key of Object.keys(group)) {
@ -987,10 +989,18 @@ function validateNonEmptyCssValue(
value: string, value: string,
issues: EidosValidationIssue[] issues: EidosValidationIssue[]
): void { ): void {
if (value.trim() !== '') return if (value.trim() === '') {
issues.push({
path,
message: 'CSS value cannot be empty'
})
return
}
if (!/[;{}]/.test(value)) return
issues.push({ issues.push({
path, path,
message: 'CSS value cannot be empty' message: 'CSS value cannot contain declaration or block delimiters'
}) })
} }

Loading…
Cancel
Save

Powered by TurnKey Linux.