Skip to content

fix(varlock): treat url(allowedDomains) comma-strings as host lists - #10

Closed
WalksWithASwagger wants to merge 1 commit into
mainfrom
cursor/fix-url-allowed-domains-21b2
Closed

fix(varlock): treat url(allowedDomains) comma-strings as host lists#10
WalksWithASwagger wants to merge 1 commit into
mainfrom
cursor/fix-url-allowed-domains-21b2

Conversation

@WalksWithASwagger

Copy link
Copy Markdown
Owner

Summary

url(allowedDomains="example.com") was validated with String.prototype.includes, so substring hosts like ample.com passed. Rejecting a bad host also threw when building the error message (.join on a string).

Changes

  • Normalize allowedDomains from a comma-string or array into a trimmed lowercase host list
  • Exact membership check + safe rejection message

Test plan

  • bunx vitest run src/env-graph/test/data-types.test.ts -t allowedDomains

Open on upstream (as WalksWithASwagger):
https://github.com/dmno-dev/varlock/compare/main...WalksWithASwagger:varlock:cursor/fix-url-allowed-domains-21b2?expand=1

Open in Web Open in Cursor 

Schema syntax often passes allowedDomains as a quoted comma-string.
String.includes was substring matching (ample.com passed for example.com)
and .join on reject threw. Normalize to a trimmed host list first.
@github-actions

Copy link
Copy Markdown

bumpy-frog

The changes in this PR will be included in the next version bump.

patch Patch releases

  • varlock 1.14.1 → 1.14.2

Bump files in this PR

Click here if you want to add another bump file to this PR


This comment is maintained by bumpy.

@github-actions

Copy link
Copy Markdown

📦 Bundle size

⚠️ grows the bundle by 1.2 KB (+0.0%)

Metric main This PR Δ
Total dist 4922.2 KB 4923.3 KB +1.2 KB (+0.0%)
JS 1692.0 KB 1692.2 KB +0.2 KB (+0.0%)
Sourcemaps 3154.2 KB 3155.1 KB +0.9 KB (+0.0%)
Type defs 76.0 KB 76.0 KB

dist/ only; native binaries are versioned separately and not counted here.

@WalksWithASwagger

Copy link
Copy Markdown
Owner Author

Landed on current main via #17 (rebased onto dmno-dev/varlock main). Closing this stale branch PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant