Repository navigation
[chore] fix sonar issues: replaceAll, globalThis, a11y, Readonly props, ReDoS - #5
Merged
Merged
Conversation
…s, ReDoS Sweeps the 70 SonarQube issues open on pathorsAI_pensieve plus the 6 security hotspots. No behaviour change intended. - S7781 replace(/…/g) -> replaceAll (mcp, search, github, extract, markdown, auth, route) - S7764 window -> globalThis (consent-form, login-panel) - S7758 charCodeAt/fromCharCode -> codePointAt/fromCodePoint - S6594 String.match -> RegExp.exec (markdown, extract, graph-view) - S6759 props typed Readonly<…> (10 components) - S6479 array-index keys -> stable keys (members table, skeleton rows) - S6478 Folder/DocLink/RelLink lifted out of GraphView to module scope, deps passed as props - S6848/S6844/S1082 clickable spans and a bare <a> become <button>s with aria-expanded/aria-label - S3358 nested ternaries flattened (graph-view draw loop, accept-client) - S7735 negated condition inverted (accept-client) - S2681 the two independent `if`s in LocalGraph get braces and their own lines — both branches were already correct, only the layout was misleading - S7769 Math.sqrt(dx*dx+dy*dy) -> Math.hypot - S1090 iframe gets a title - S4325 drop the non-null assertion in lib/db.ts in favour of an explicit DATABASE_URL check (neon() already threw at module load without one) Hotspots: two S5852 rewritten to non-backtracking equivalents (github.ts b64url trailing "=", markdown.ts frontmatter/h1 patterns); the rest reviewed and left as-is. Verified: bunx tsc --noEmit and next build both clean.
❌ SonarQube Quality Gate ERROR — pathorsAI_pensieve
1 open issue on this PR:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Sweeps the 70 SonarQube issues open on
pathorsAI_pensieveplus the 6 security hotspots. No behaviour change intended.Fixed (70/70)
replace(/…/g, …)→replaceAll(only where equivalent: string first arg org-flag regex)lib/mcp.ts,lib/search.ts,lib/github.ts,lib/extract.ts,lib/markdown.ts,lib/auth.ts,app/o/[slug]/d/[...path]/route.tswindow→globalThis(SSR guard kept astypeof globalThis.window === "undefined")app/consent/consent-form.tsx,app/login/login-panel.tsxcharCodeAt→codePointAt,String.fromCharCode→fromCodePoint(all byte values 0–255, so identical)lib/github.ts,route.tsString.match→RegExp.execlib/markdown.ts,lib/extract.ts,graph-view.tsxReadonly<…>key→ stable key (m.email; skeleton widths are distinct)members/page.tsx,graph-view.tsxFolder/DocLink/RelLinklifted out ofGraphViewinto module scope, dependencies passed as propsgraph-view.tsx<span>s (disclosure arrow, folder name) and a bare<a>("清除") become<button type="button">witharia-expanded/aria-labelgraph-view.tsxgraph-view.tsx,accept-client.tsx!session ? … : …invertedaccept-client.tsxifs on one line get braces and their own linesgraph-view.tsxMath.sqrt(dx*dx + dy*dy)→Math.hypot(dx, dy)graph-view.tsx<iframe>gets atitlegraph-view.tsxDATABASE_URLchecklib/db.tsNotes on the two judgement calls:
LocalGraphwas not a real bug.if (e.from === center) near.add(e.to); if (e.to === center) near.add(e.from);— an edge can touchcenterat either end and both checks were already independent and correct. Only the one-line layout was misleading; it now has braces and a comment.lib/db.tslooked like a false positive —tscconfirmsprocess.env.DATABASE_URL!genuinely needs the assertion understrict. Rather than suppress it, the variable is now checked explicitly.neon()already threw at module load when the variable was unset, so the failure point is unchanged; the message is just clearer.Security hotspots
lib/extract.ts:44S5852/<[^>]+>/g: the negated class and the closing>are disjoint, so the match is deterministic and runs in linear time with no backtracking.lib/github.ts:9S5852/=+$/(polynomial on a run of=) replaced with awhile (s.endsWith("="))loop; equivalent for base64 output and unambiguously linear.lib/markdown.ts:13S5852$from/^(\w[\w-]*):\s*(.*)$/, removing the\s*/.*backtracking; the greedy.*already runs to the end of the (newline-free) frontmatter line.lib/markdown.ts:17S5852/^#\s+(.+)$/m→/^#\s+(\S.*)$/m;\Sis disjoint from the preceding\s+, so each backtrack fails in O(1).app/o/[slug]/graph-view.tsx:44S2245Math.random()only jitters initial node positions in the force-directed layout; it is decorative, never used for tokens, ids, or any security decision.app/o/[slug]/graph-view.tsx:44S2245Both markdown rewrites and the base64 trim were diffed against the originals over a table of inputs (frontmatter lines, headings with mixed whitespace, padded/unpadded base64) — identical output in every case.
Verification
bunx tsc --noEmitandbun run build(Next.js 15) both clean. Note this repo has no CI workflow yet.