mirror of
https://github.com/openclaw/openclaw.git
synced 2026-08-12 21:53:00 -06:00
refactor: consolidate coercion contracts (#122458)
* refactor: consolidate coercion contracts Centralize exact string, record, numeric, date, Boolean, argument, and structured-error coercions while preserving call-site semantics. Migrate canonical-name collisions and deprecated internal SDK bypasses, deleting 55 net production/tooling lines. Expand declaration ownership enforcement to 101 allowed helpers and add a narrow export-completeness audit. * fix: preserve standalone script coercions Keep copied Control UI tooling self-contained and retain the trusted release harness module-relative source seam when the harness runs against an old target cwd.
This commit is contained in:
committed by
GitHub
parent
66fe424590
commit
b080dd1e76
@@ -30,7 +30,7 @@ export async function readRules(rulepackPath) {
|
||||
return data.rules;
|
||||
}
|
||||
|
||||
function hasNonEmptyString(value) {
|
||||
function hasRuleMetadataText(value) {
|
||||
return typeof value === "string" && value.trim().length > 0;
|
||||
}
|
||||
|
||||
@@ -68,7 +68,7 @@ export function validateRuleMetadata(rules) {
|
||||
const advisoryId = String(metadata["advisory-id"] ?? metadata.ghsa ?? "")
|
||||
.trim()
|
||||
.toUpperCase();
|
||||
if (!hasNonEmptyString(advisoryId)) {
|
||||
if (!hasRuleMetadataText(advisoryId)) {
|
||||
violations.push(`${label}: missing metadata.advisory-id or metadata.ghsa`);
|
||||
} else if (idMatch && idMatch[1] !== sanitizeSourceIdComponent(advisoryId)) {
|
||||
violations.push(
|
||||
@@ -88,7 +88,7 @@ export function validateRuleMetadata(rules) {
|
||||
const expectedGhsaUrl = GHSA_RE.test(advisoryId)
|
||||
? `https://github.com/openclaw/openclaw/security/advisories/${advisoryId}`
|
||||
: "";
|
||||
if (!hasNonEmptyString(advisoryUrl)) {
|
||||
if (!hasRuleMetadataText(advisoryUrl)) {
|
||||
violations.push(`${label}: missing metadata.advisory-url`);
|
||||
} else if (expectedGhsaUrl && advisoryUrl !== expectedGhsaUrl) {
|
||||
violations.push(`${label}: metadata.advisory-url must be ${expectedGhsaUrl}`);
|
||||
@@ -97,7 +97,7 @@ export function validateRuleMetadata(rules) {
|
||||
if (metadata["detector-bucket"] !== "precise") {
|
||||
violations.push(`${label}: metadata.detector-bucket must be precise`);
|
||||
}
|
||||
if (!hasNonEmptyString(metadata["source-rule-id"])) {
|
||||
if (!hasRuleMetadataText(metadata["source-rule-id"])) {
|
||||
violations.push(`${label}: missing metadata.source-rule-id`);
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user