chore: use the extracted stringify-package module - #21

Merged
zkat merged 1 commit into
npm:release-nextfrom
dpogue:stringify-package
Jul 19, 2018
Merged

chore: use the extracted stringify-package module#21
zkat merged 1 commit into
npm:release-nextfrom
dpogue:stringify-package

Conversation

@dpogue

Copy link
Copy Markdown
Contributor

stringify-package has been extracted into its own module.

Not sure if I should be committing the stringify-package folder under node_modules and adding it to bundledDependencies as well?

@dpogue
dpogue requested a review from a team as a code ownerJuly 18, 2018 18:45
@zkat

zkat commented Jul 18, 2018

Copy link
Copy Markdown
Contributor

@dpogue In order to add a dependency, you need to:

  1. npm install -B <dep> (-B bundles it)
  2. git add -A node_modules package.json package-lock.json
  3. git commit

We keep all our deps in the repo.

@dpogue
dpogueforce-pushed the stringify-package branch from 3df0d1c to 340e34fCompareJuly 18, 2018 22:34
@dpogue

Copy link
Copy Markdown
ContributorAuthor

Thanks @zkat. Updated to bundle the dependency and now all the CI tests are green :)

@zkatzkat left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking care of that. This lgtm and I think we're gtg!

@zkat
zkat changed the base branch from latest to release-nextJuly 19, 2018 00:54
@zkat
zkat merged commit a9ac871 into npm:release-nextJul 19, 2018
@dpogue
dpogue deleted the stringify-package branch July 19, 2018 06:37
koralle pushed a commit to koralle/npm-cli that referenced this pull request Feb 11, 2026
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
)
* refactor: replace manual urlencoded() with reqwest .query() builder
Remove duplicate hand-rolled urlencoded() functions from workflows.rs
and calendar.rs. All query parameters are now passed via reqwest's
.query() API, which handles percent-encoding correctly and completely.
* fix: percent-encode path parameters to prevent path traversal
Use percent_encoding::utf8_percent_encode for calendar_id, cal.id,
message_id, and file_id before interpolating into URL path segments.
Addresses code review feedback on security regression.
* fix: add shared URL safety helpers for path params
Add encode_path_segment() for single-segment IDs and
validate_resource_name() for multi-segment resource names.
encode_path_segment: percent-encodes all non-alphanumeric chars,
used for calendar IDs, file IDs, and message IDs.
validate_resource_name: rejects path traversal (..) and control
chars while preserving intentional / structure, used for Chat
space names, task list IDs, and subscription names. Returns clear
error messages for LLM callers.
* test: add AI edge case tests for URL safety helpers
Cover query/fragment injection, double-encoding, unicode, spaces,
path traversal via encoding, control chars (CR/tab), and clear
error message assertions for LLM callers.
* fix: warn on stderr when API calls fail silently
- Daily briefing calendar events fetch
- Daily briefing tasks fetch
- Daily summary calendar events fetch
- Daily summary unread email count fetch
Addresses PR review feedback about confusing silent failures,
especially for LLM callers that cannot see visual cues.
* fix: harden input validation for AI/LLM callers
- Add src/validate.rs with validate_safe_output_dir, validate_msg_format,
and validate_safe_dir_path helpers
- Validate --output-dir against path traversal in gmail +watch and
events +subscribe
- Validate --msg-format against allowlist in gmail +watch
- Validate --dir against path traversal in script +push
- Add clap value_parser constraint for --msg-format
- Document input validation patterns in AGENTS.md
Closesnpm#23
* chore: add changesets for PR npm#21 commits
* test: add comprehensive test coverage for input validation handlers
* docs: document input validation and URL safety patterns in AGENTS.md and CONTRIBUTING.md
* fix: address PR review comments — reject ?/# in resource names, validate subscription arg, remove redundant validate_msg_format
* fix: store validated PathBuf, remove dead code, delete duplicate SubscribeConfig
Addresses review comments:
- Store validated PathBuf from validate_safe_output_dir instead of
discarding it (output_dir is now Option<PathBuf>)
- Remove duplicate SubscribeConfig from events/mod.rs
- Delete unused validate_msg_format (clap value_parser handles this)
- Remove all #[allow(dead_code)] annotations
* fix: per-segment traversal check in validate_resource_name, fix docs
* fix: harden security validation and deduplicate logic
---------
Co-authored-by: jpoehnelt-bot <jpoehnelt-bot@users.noreply.github.com>
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 5, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 30, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 3, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 25, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 2, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 8, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@dpogue@zkat
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore: use the extracted stringify-package module - #21

Merged
zkat merged 1 commit into
npm:release-nextfrom
dpogue:stringify-package
Jul 19, 2018
Merged

chore: use the extracted stringify-package module#21
zkat merged 1 commit into
npm:release-nextfrom
dpogue:stringify-package

Conversation

@dpogue

Copy link
Copy Markdown
Contributor

stringify-package has been extracted into its own module.

Not sure if I should be committing the stringify-package folder under node_modules and adding it to bundledDependencies as well?

@dpogue
dpogue requested a review from a team as a code ownerJuly 18, 2018 18:45
@zkat

zkat commented Jul 18, 2018

Copy link
Copy Markdown
Contributor

@dpogue In order to add a dependency, you need to:

  1. npm install -B <dep> (-B bundles it)
  2. git add -A node_modules package.json package-lock.json
  3. git commit

We keep all our deps in the repo.

@dpogue
dpogueforce-pushed the stringify-package branch from 3df0d1c to 340e34fCompareJuly 18, 2018 22:34
@dpogue

Copy link
Copy Markdown
ContributorAuthor

Thanks @zkat. Updated to bundle the dependency and now all the CI tests are green :)

@zkatzkat left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking care of that. This lgtm and I think we're gtg!

@zkat
zkat changed the base branch from latest to release-nextJuly 19, 2018 00:54
@zkat
zkat merged commit a9ac871 into npm:release-nextJul 19, 2018
@dpogue
dpogue deleted the stringify-package branch July 19, 2018 06:37
koralle pushed a commit to koralle/npm-cli that referenced this pull request Feb 11, 2026
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
)
* refactor: replace manual urlencoded() with reqwest .query() builder
Remove duplicate hand-rolled urlencoded() functions from workflows.rs
and calendar.rs. All query parameters are now passed via reqwest's
.query() API, which handles percent-encoding correctly and completely.
* fix: percent-encode path parameters to prevent path traversal
Use percent_encoding::utf8_percent_encode for calendar_id, cal.id,
message_id, and file_id before interpolating into URL path segments.
Addresses code review feedback on security regression.
* fix: add shared URL safety helpers for path params
Add encode_path_segment() for single-segment IDs and
validate_resource_name() for multi-segment resource names.
encode_path_segment: percent-encodes all non-alphanumeric chars,
used for calendar IDs, file IDs, and message IDs.
validate_resource_name: rejects path traversal (..) and control
chars while preserving intentional / structure, used for Chat
space names, task list IDs, and subscription names. Returns clear
error messages for LLM callers.
* test: add AI edge case tests for URL safety helpers
Cover query/fragment injection, double-encoding, unicode, spaces,
path traversal via encoding, control chars (CR/tab), and clear
error message assertions for LLM callers.
* fix: warn on stderr when API calls fail silently
- Daily briefing calendar events fetch
- Daily briefing tasks fetch
- Daily summary calendar events fetch
- Daily summary unread email count fetch
Addresses PR review feedback about confusing silent failures,
especially for LLM callers that cannot see visual cues.
* fix: harden input validation for AI/LLM callers
- Add src/validate.rs with validate_safe_output_dir, validate_msg_format,
and validate_safe_dir_path helpers
- Validate --output-dir against path traversal in gmail +watch and
events +subscribe
- Validate --msg-format against allowlist in gmail +watch
- Validate --dir against path traversal in script +push
- Add clap value_parser constraint for --msg-format
- Document input validation patterns in AGENTS.md
Closesnpm#23
* chore: add changesets for PR npm#21 commits
* test: add comprehensive test coverage for input validation handlers
* docs: document input validation and URL safety patterns in AGENTS.md and CONTRIBUTING.md
* fix: address PR review comments — reject ?/# in resource names, validate subscription arg, remove redundant validate_msg_format
* fix: store validated PathBuf, remove dead code, delete duplicate SubscribeConfig
Addresses review comments:
- Store validated PathBuf from validate_safe_output_dir instead of
discarding it (output_dir is now Option<PathBuf>)
- Remove duplicate SubscribeConfig from events/mod.rs
- Delete unused validate_msg_format (clap value_parser handles this)
- Remove all #[allow(dead_code)] annotations
* fix: per-segment traversal check in validate_resource_name, fix docs
* fix: harden security validation and deduplicate logic
---------
Co-authored-by: jpoehnelt-bot <jpoehnelt-bot@users.noreply.github.com>
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 5, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 30, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 3, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 25, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 2, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 8, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@dpogue@zkat
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: use the extracted stringify-package module - #21

Merged
zkat merged 1 commit into
npm:release-nextfrom
dpogue:stringify-package
Jul 19, 2018
Merged

chore: use the extracted stringify-package module#21
zkat merged 1 commit into
npm:release-nextfrom
dpogue:stringify-package

Conversation

@dpogue

Copy link
Copy Markdown
Contributor

stringify-package has been extracted into its own module.

Not sure if I should be committing the stringify-package folder under node_modules and adding it to bundledDependencies as well?

@dpogue
dpogue requested a review from a team as a code ownerJuly 18, 2018 18:45
@zkat

zkat commented Jul 18, 2018

Copy link
Copy Markdown
Contributor

@dpogue In order to add a dependency, you need to:

  1. npm install -B <dep> (-B bundles it)
  2. git add -A node_modules package.json package-lock.json
  3. git commit

We keep all our deps in the repo.

@dpogue
dpogueforce-pushed the stringify-package branch from 3df0d1c to 340e34fCompareJuly 18, 2018 22:34
@dpogue

Copy link
Copy Markdown
ContributorAuthor

Thanks @zkat. Updated to bundle the dependency and now all the CI tests are green :)

@zkatzkat left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking care of that. This lgtm and I think we're gtg!

@zkat
zkat changed the base branch from latest to release-nextJuly 19, 2018 00:54
@zkat
zkat merged commit a9ac871 into npm:release-nextJul 19, 2018
@dpogue
dpogue deleted the stringify-package branch July 19, 2018 06:37
koralle pushed a commit to koralle/npm-cli that referenced this pull request Feb 11, 2026
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
)
* refactor: replace manual urlencoded() with reqwest .query() builder
Remove duplicate hand-rolled urlencoded() functions from workflows.rs
and calendar.rs. All query parameters are now passed via reqwest's
.query() API, which handles percent-encoding correctly and completely.
* fix: percent-encode path parameters to prevent path traversal
Use percent_encoding::utf8_percent_encode for calendar_id, cal.id,
message_id, and file_id before interpolating into URL path segments.
Addresses code review feedback on security regression.
* fix: add shared URL safety helpers for path params
Add encode_path_segment() for single-segment IDs and
validate_resource_name() for multi-segment resource names.
encode_path_segment: percent-encodes all non-alphanumeric chars,
used for calendar IDs, file IDs, and message IDs.
validate_resource_name: rejects path traversal (..) and control
chars while preserving intentional / structure, used for Chat
space names, task list IDs, and subscription names. Returns clear
error messages for LLM callers.
* test: add AI edge case tests for URL safety helpers
Cover query/fragment injection, double-encoding, unicode, spaces,
path traversal via encoding, control chars (CR/tab), and clear
error message assertions for LLM callers.
* fix: warn on stderr when API calls fail silently
- Daily briefing calendar events fetch
- Daily briefing tasks fetch
- Daily summary calendar events fetch
- Daily summary unread email count fetch
Addresses PR review feedback about confusing silent failures,
especially for LLM callers that cannot see visual cues.
* fix: harden input validation for AI/LLM callers
- Add src/validate.rs with validate_safe_output_dir, validate_msg_format,
and validate_safe_dir_path helpers
- Validate --output-dir against path traversal in gmail +watch and
events +subscribe
- Validate --msg-format against allowlist in gmail +watch
- Validate --dir against path traversal in script +push
- Add clap value_parser constraint for --msg-format
- Document input validation patterns in AGENTS.md
Closesnpm#23
* chore: add changesets for PR npm#21 commits
* test: add comprehensive test coverage for input validation handlers
* docs: document input validation and URL safety patterns in AGENTS.md and CONTRIBUTING.md
* fix: address PR review comments — reject ?/# in resource names, validate subscription arg, remove redundant validate_msg_format
* fix: store validated PathBuf, remove dead code, delete duplicate SubscribeConfig
Addresses review comments:
- Store validated PathBuf from validate_safe_output_dir instead of
discarding it (output_dir is now Option<PathBuf>)
- Remove duplicate SubscribeConfig from events/mod.rs
- Delete unused validate_msg_format (clap value_parser handles this)
- Remove all #[allow(dead_code)] annotations
* fix: per-segment traversal check in validate_resource_name, fix docs
* fix: harden security validation and deduplicate logic
---------
Co-authored-by: jpoehnelt-bot <jpoehnelt-bot@users.noreply.github.com>
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 5, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 30, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 3, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 25, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 2, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 8, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@dpogue@zkat
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: use the extracted stringify-package module - #21

Merged
zkat merged 1 commit into
npm:release-nextfrom
dpogue:stringify-package
Jul 19, 2018
Merged

chore: use the extracted stringify-package module#21
zkat merged 1 commit into
npm:release-nextfrom
dpogue:stringify-package

Conversation

@dpogue

Copy link
Copy Markdown
Contributor

stringify-package has been extracted into its own module.

Not sure if I should be committing the stringify-package folder under node_modules and adding it to bundledDependencies as well?

@dpogue
dpogue requested a review from a team as a code ownerJuly 18, 2018 18:45
@zkat

zkat commented Jul 18, 2018

Copy link
Copy Markdown
Contributor

@dpogue In order to add a dependency, you need to:

  1. npm install -B <dep> (-B bundles it)
  2. git add -A node_modules package.json package-lock.json
  3. git commit

We keep all our deps in the repo.

@dpogue
dpogueforce-pushed the stringify-package branch from 3df0d1c to 340e34fCompareJuly 18, 2018 22:34
@dpogue

Copy link
Copy Markdown
ContributorAuthor

Thanks @zkat. Updated to bundle the dependency and now all the CI tests are green :)

@zkatzkat left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking care of that. This lgtm and I think we're gtg!

@zkat
zkat changed the base branch from latest to release-nextJuly 19, 2018 00:54
@zkat
zkat merged commit a9ac871 into npm:release-nextJul 19, 2018
@dpogue
dpogue deleted the stringify-package branch July 19, 2018 06:37
koralle pushed a commit to koralle/npm-cli that referenced this pull request Feb 11, 2026
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
)
* refactor: replace manual urlencoded() with reqwest .query() builder
Remove duplicate hand-rolled urlencoded() functions from workflows.rs
and calendar.rs. All query parameters are now passed via reqwest's
.query() API, which handles percent-encoding correctly and completely.
* fix: percent-encode path parameters to prevent path traversal
Use percent_encoding::utf8_percent_encode for calendar_id, cal.id,
message_id, and file_id before interpolating into URL path segments.
Addresses code review feedback on security regression.
* fix: add shared URL safety helpers for path params
Add encode_path_segment() for single-segment IDs and
validate_resource_name() for multi-segment resource names.
encode_path_segment: percent-encodes all non-alphanumeric chars,
used for calendar IDs, file IDs, and message IDs.
validate_resource_name: rejects path traversal (..) and control
chars while preserving intentional / structure, used for Chat
space names, task list IDs, and subscription names. Returns clear
error messages for LLM callers.
* test: add AI edge case tests for URL safety helpers
Cover query/fragment injection, double-encoding, unicode, spaces,
path traversal via encoding, control chars (CR/tab), and clear
error message assertions for LLM callers.
* fix: warn on stderr when API calls fail silently
- Daily briefing calendar events fetch
- Daily briefing tasks fetch
- Daily summary calendar events fetch
- Daily summary unread email count fetch
Addresses PR review feedback about confusing silent failures,
especially for LLM callers that cannot see visual cues.
* fix: harden input validation for AI/LLM callers
- Add src/validate.rs with validate_safe_output_dir, validate_msg_format,
and validate_safe_dir_path helpers
- Validate --output-dir against path traversal in gmail +watch and
events +subscribe
- Validate --msg-format against allowlist in gmail +watch
- Validate --dir against path traversal in script +push
- Add clap value_parser constraint for --msg-format
- Document input validation patterns in AGENTS.md
Closesnpm#23
* chore: add changesets for PR npm#21 commits
* test: add comprehensive test coverage for input validation handlers
* docs: document input validation and URL safety patterns in AGENTS.md and CONTRIBUTING.md
* fix: address PR review comments — reject ?/# in resource names, validate subscription arg, remove redundant validate_msg_format
* fix: store validated PathBuf, remove dead code, delete duplicate SubscribeConfig
Addresses review comments:
- Store validated PathBuf from validate_safe_output_dir instead of
discarding it (output_dir is now Option<PathBuf>)
- Remove duplicate SubscribeConfig from events/mod.rs
- Delete unused validate_msg_format (clap value_parser handles this)
- Remove all #[allow(dead_code)] annotations
* fix: per-segment traversal check in validate_resource_name, fix docs
* fix: harden security validation and deduplicate logic
---------
Co-authored-by: jpoehnelt-bot <jpoehnelt-bot@users.noreply.github.com>
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 5, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 30, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 3, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 25, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 2, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 8, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@dpogue@zkat
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore: use the extracted stringify-package module - #21

Merged
zkat merged 1 commit into
npm:release-nextfrom
dpogue:stringify-package
Jul 19, 2018
Merged

chore: use the extracted stringify-package module#21
zkat merged 1 commit into
npm:release-nextfrom
dpogue:stringify-package

Conversation

@dpogue

Copy link
Copy Markdown
Contributor

stringify-package has been extracted into its own module.

Not sure if I should be committing the stringify-package folder under node_modules and adding it to bundledDependencies as well?

@dpogue
dpogue requested a review from a team as a code ownerJuly 18, 2018 18:45
@zkat

zkat commented Jul 18, 2018

Copy link
Copy Markdown
Contributor

@dpogue In order to add a dependency, you need to:

  1. npm install -B <dep> (-B bundles it)
  2. git add -A node_modules package.json package-lock.json
  3. git commit

We keep all our deps in the repo.

@dpogue
dpogueforce-pushed the stringify-package branch from 3df0d1c to 340e34fCompareJuly 18, 2018 22:34
@dpogue

Copy link
Copy Markdown
ContributorAuthor

Thanks @zkat. Updated to bundle the dependency and now all the CI tests are green :)

@zkatzkat left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking care of that. This lgtm and I think we're gtg!

@zkat
zkat changed the base branch from latest to release-nextJuly 19, 2018 00:54
@zkat
zkat merged commit a9ac871 into npm:release-nextJul 19, 2018
@dpogue
dpogue deleted the stringify-package branch July 19, 2018 06:37
koralle pushed a commit to koralle/npm-cli that referenced this pull request Feb 11, 2026
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
)
* refactor: replace manual urlencoded() with reqwest .query() builder
Remove duplicate hand-rolled urlencoded() functions from workflows.rs
and calendar.rs. All query parameters are now passed via reqwest's
.query() API, which handles percent-encoding correctly and completely.
* fix: percent-encode path parameters to prevent path traversal
Use percent_encoding::utf8_percent_encode for calendar_id, cal.id,
message_id, and file_id before interpolating into URL path segments.
Addresses code review feedback on security regression.
* fix: add shared URL safety helpers for path params
Add encode_path_segment() for single-segment IDs and
validate_resource_name() for multi-segment resource names.
encode_path_segment: percent-encodes all non-alphanumeric chars,
used for calendar IDs, file IDs, and message IDs.
validate_resource_name: rejects path traversal (..) and control
chars while preserving intentional / structure, used for Chat
space names, task list IDs, and subscription names. Returns clear
error messages for LLM callers.
* test: add AI edge case tests for URL safety helpers
Cover query/fragment injection, double-encoding, unicode, spaces,
path traversal via encoding, control chars (CR/tab), and clear
error message assertions for LLM callers.
* fix: warn on stderr when API calls fail silently
- Daily briefing calendar events fetch
- Daily briefing tasks fetch
- Daily summary calendar events fetch
- Daily summary unread email count fetch
Addresses PR review feedback about confusing silent failures,
especially for LLM callers that cannot see visual cues.
* fix: harden input validation for AI/LLM callers
- Add src/validate.rs with validate_safe_output_dir, validate_msg_format,
and validate_safe_dir_path helpers
- Validate --output-dir against path traversal in gmail +watch and
events +subscribe
- Validate --msg-format against allowlist in gmail +watch
- Validate --dir against path traversal in script +push
- Add clap value_parser constraint for --msg-format
- Document input validation patterns in AGENTS.md
Closesnpm#23
* chore: add changesets for PR npm#21 commits
* test: add comprehensive test coverage for input validation handlers
* docs: document input validation and URL safety patterns in AGENTS.md and CONTRIBUTING.md
* fix: address PR review comments — reject ?/# in resource names, validate subscription arg, remove redundant validate_msg_format
* fix: store validated PathBuf, remove dead code, delete duplicate SubscribeConfig
Addresses review comments:
- Store validated PathBuf from validate_safe_output_dir instead of
discarding it (output_dir is now Option<PathBuf>)
- Remove duplicate SubscribeConfig from events/mod.rs
- Delete unused validate_msg_format (clap value_parser handles this)
- Remove all #[allow(dead_code)] annotations
* fix: per-segment traversal check in validate_resource_name, fix docs
* fix: harden security validation and deduplicate logic
---------
Co-authored-by: jpoehnelt-bot <jpoehnelt-bot@users.noreply.github.com>
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 5, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 30, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 3, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 25, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 2, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 8, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@dpogue@zkat
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: use the extracted stringify-package module - #21

Merged
zkat merged 1 commit into
npm:release-nextfrom
dpogue:stringify-package
Jul 19, 2018
Merged

chore: use the extracted stringify-package module#21
zkat merged 1 commit into
npm:release-nextfrom
dpogue:stringify-package

Conversation

@dpogue

Copy link
Copy Markdown
Contributor

stringify-package has been extracted into its own module.

Not sure if I should be committing the stringify-package folder under node_modules and adding it to bundledDependencies as well?

@dpogue
dpogue requested a review from a team as a code ownerJuly 18, 2018 18:45
@zkat

zkat commented Jul 18, 2018

Copy link
Copy Markdown
Contributor

@dpogue In order to add a dependency, you need to:

  1. npm install -B <dep> (-B bundles it)
  2. git add -A node_modules package.json package-lock.json
  3. git commit

We keep all our deps in the repo.

@dpogue
dpogueforce-pushed the stringify-package branch from 3df0d1c to 340e34fCompareJuly 18, 2018 22:34
@dpogue

Copy link
Copy Markdown
ContributorAuthor

Thanks @zkat. Updated to bundle the dependency and now all the CI tests are green :)

@zkatzkat left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking care of that. This lgtm and I think we're gtg!

@zkat
zkat changed the base branch from latest to release-nextJuly 19, 2018 00:54
@zkat
zkat merged commit a9ac871 into npm:release-nextJul 19, 2018
@dpogue
dpogue deleted the stringify-package branch July 19, 2018 06:37
koralle pushed a commit to koralle/npm-cli that referenced this pull request Feb 11, 2026
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
)
* refactor: replace manual urlencoded() with reqwest .query() builder
Remove duplicate hand-rolled urlencoded() functions from workflows.rs
and calendar.rs. All query parameters are now passed via reqwest's
.query() API, which handles percent-encoding correctly and completely.
* fix: percent-encode path parameters to prevent path traversal
Use percent_encoding::utf8_percent_encode for calendar_id, cal.id,
message_id, and file_id before interpolating into URL path segments.
Addresses code review feedback on security regression.
* fix: add shared URL safety helpers for path params
Add encode_path_segment() for single-segment IDs and
validate_resource_name() for multi-segment resource names.
encode_path_segment: percent-encodes all non-alphanumeric chars,
used for calendar IDs, file IDs, and message IDs.
validate_resource_name: rejects path traversal (..) and control
chars while preserving intentional / structure, used for Chat
space names, task list IDs, and subscription names. Returns clear
error messages for LLM callers.
* test: add AI edge case tests for URL safety helpers
Cover query/fragment injection, double-encoding, unicode, spaces,
path traversal via encoding, control chars (CR/tab), and clear
error message assertions for LLM callers.
* fix: warn on stderr when API calls fail silently
- Daily briefing calendar events fetch
- Daily briefing tasks fetch
- Daily summary calendar events fetch
- Daily summary unread email count fetch
Addresses PR review feedback about confusing silent failures,
especially for LLM callers that cannot see visual cues.
* fix: harden input validation for AI/LLM callers
- Add src/validate.rs with validate_safe_output_dir, validate_msg_format,
and validate_safe_dir_path helpers
- Validate --output-dir against path traversal in gmail +watch and
events +subscribe
- Validate --msg-format against allowlist in gmail +watch
- Validate --dir against path traversal in script +push
- Add clap value_parser constraint for --msg-format
- Document input validation patterns in AGENTS.md
Closesnpm#23
* chore: add changesets for PR npm#21 commits
* test: add comprehensive test coverage for input validation handlers
* docs: document input validation and URL safety patterns in AGENTS.md and CONTRIBUTING.md
* fix: address PR review comments — reject ?/# in resource names, validate subscription arg, remove redundant validate_msg_format
* fix: store validated PathBuf, remove dead code, delete duplicate SubscribeConfig
Addresses review comments:
- Store validated PathBuf from validate_safe_output_dir instead of
discarding it (output_dir is now Option<PathBuf>)
- Remove duplicate SubscribeConfig from events/mod.rs
- Delete unused validate_msg_format (clap value_parser handles this)
- Remove all #[allow(dead_code)] annotations
* fix: per-segment traversal check in validate_resource_name, fix docs
* fix: harden security validation and deduplicate logic
---------
Co-authored-by: jpoehnelt-bot <jpoehnelt-bot@users.noreply.github.com>
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 5, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 30, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 3, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 25, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 2, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 8, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@dpogue@zkat
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: use the extracted stringify-package module - #21

Merged
zkat merged 1 commit into
npm:release-nextfrom
dpogue:stringify-package
Jul 19, 2018
Merged

chore: use the extracted stringify-package module#21
zkat merged 1 commit into
npm:release-nextfrom
dpogue:stringify-package

Conversation

@dpogue

Copy link
Copy Markdown
Contributor

stringify-package has been extracted into its own module.

Not sure if I should be committing the stringify-package folder under node_modules and adding it to bundledDependencies as well?

@dpogue
dpogue requested a review from a team as a code ownerJuly 18, 2018 18:45
@zkat

zkat commented Jul 18, 2018

Copy link
Copy Markdown
Contributor

@dpogue In order to add a dependency, you need to:

  1. npm install -B <dep> (-B bundles it)
  2. git add -A node_modules package.json package-lock.json
  3. git commit

We keep all our deps in the repo.

@dpogue
dpogueforce-pushed the stringify-package branch from 3df0d1c to 340e34fCompareJuly 18, 2018 22:34
@dpogue

Copy link
Copy Markdown
ContributorAuthor

Thanks @zkat. Updated to bundle the dependency and now all the CI tests are green :)

@zkatzkat left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking care of that. This lgtm and I think we're gtg!

@zkat
zkat changed the base branch from latest to release-nextJuly 19, 2018 00:54
@zkat
zkat merged commit a9ac871 into npm:release-nextJul 19, 2018
@dpogue
dpogue deleted the stringify-package branch July 19, 2018 06:37
koralle pushed a commit to koralle/npm-cli that referenced this pull request Feb 11, 2026
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
)
* refactor: replace manual urlencoded() with reqwest .query() builder
Remove duplicate hand-rolled urlencoded() functions from workflows.rs
and calendar.rs. All query parameters are now passed via reqwest's
.query() API, which handles percent-encoding correctly and completely.
* fix: percent-encode path parameters to prevent path traversal
Use percent_encoding::utf8_percent_encode for calendar_id, cal.id,
message_id, and file_id before interpolating into URL path segments.
Addresses code review feedback on security regression.
* fix: add shared URL safety helpers for path params
Add encode_path_segment() for single-segment IDs and
validate_resource_name() for multi-segment resource names.
encode_path_segment: percent-encodes all non-alphanumeric chars,
used for calendar IDs, file IDs, and message IDs.
validate_resource_name: rejects path traversal (..) and control
chars while preserving intentional / structure, used for Chat
space names, task list IDs, and subscription names. Returns clear
error messages for LLM callers.
* test: add AI edge case tests for URL safety helpers
Cover query/fragment injection, double-encoding, unicode, spaces,
path traversal via encoding, control chars (CR/tab), and clear
error message assertions for LLM callers.
* fix: warn on stderr when API calls fail silently
- Daily briefing calendar events fetch
- Daily briefing tasks fetch
- Daily summary calendar events fetch
- Daily summary unread email count fetch
Addresses PR review feedback about confusing silent failures,
especially for LLM callers that cannot see visual cues.
* fix: harden input validation for AI/LLM callers
- Add src/validate.rs with validate_safe_output_dir, validate_msg_format,
and validate_safe_dir_path helpers
- Validate --output-dir against path traversal in gmail +watch and
events +subscribe
- Validate --msg-format against allowlist in gmail +watch
- Validate --dir against path traversal in script +push
- Add clap value_parser constraint for --msg-format
- Document input validation patterns in AGENTS.md
Closesnpm#23
* chore: add changesets for PR npm#21 commits
* test: add comprehensive test coverage for input validation handlers
* docs: document input validation and URL safety patterns in AGENTS.md and CONTRIBUTING.md
* fix: address PR review comments — reject ?/# in resource names, validate subscription arg, remove redundant validate_msg_format
* fix: store validated PathBuf, remove dead code, delete duplicate SubscribeConfig
Addresses review comments:
- Store validated PathBuf from validate_safe_output_dir instead of
discarding it (output_dir is now Option<PathBuf>)
- Remove duplicate SubscribeConfig from events/mod.rs
- Delete unused validate_msg_format (clap value_parser handles this)
- Remove all #[allow(dead_code)] annotations
* fix: per-segment traversal check in validate_resource_name, fix docs
* fix: harden security validation and deduplicate logic
---------
Co-authored-by: jpoehnelt-bot <jpoehnelt-bot@users.noreply.github.com>
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 5, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 30, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 3, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 25, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 2, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 8, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@dpogue@zkat
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore: use the extracted stringify-package module - #21

Merged
zkat merged 1 commit into
npm:release-nextfrom
dpogue:stringify-package
Jul 19, 2018
Merged

chore: use the extracted stringify-package module#21
zkat merged 1 commit into
npm:release-nextfrom
dpogue:stringify-package

Conversation

@dpogue

Copy link
Copy Markdown
Contributor

stringify-package has been extracted into its own module.

Not sure if I should be committing the stringify-package folder under node_modules and adding it to bundledDependencies as well?

@dpogue
dpogue requested a review from a team as a code ownerJuly 18, 2018 18:45
@zkat

zkat commented Jul 18, 2018

Copy link
Copy Markdown
Contributor

@dpogue In order to add a dependency, you need to:

  1. npm install -B <dep> (-B bundles it)
  2. git add -A node_modules package.json package-lock.json
  3. git commit

We keep all our deps in the repo.

@dpogue
dpogueforce-pushed the stringify-package branch from 3df0d1c to 340e34fCompareJuly 18, 2018 22:34
@dpogue

Copy link
Copy Markdown
ContributorAuthor

Thanks @zkat. Updated to bundle the dependency and now all the CI tests are green :)

@zkatzkat left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Thanks for taking care of that. This lgtm and I think we're gtg!

@zkat
zkat changed the base branch from latest to release-nextJuly 19, 2018 00:54
@zkat
zkat merged commit a9ac871 into npm:release-nextJul 19, 2018
@dpogue
dpogue deleted the stringify-package branch July 19, 2018 06:37
koralle pushed a commit to koralle/npm-cli that referenced this pull request Feb 11, 2026
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
)
* refactor: replace manual urlencoded() with reqwest .query() builder
Remove duplicate hand-rolled urlencoded() functions from workflows.rs
and calendar.rs. All query parameters are now passed via reqwest's
.query() API, which handles percent-encoding correctly and completely.
* fix: percent-encode path parameters to prevent path traversal
Use percent_encoding::utf8_percent_encode for calendar_id, cal.id,
message_id, and file_id before interpolating into URL path segments.
Addresses code review feedback on security regression.
* fix: add shared URL safety helpers for path params
Add encode_path_segment() for single-segment IDs and
validate_resource_name() for multi-segment resource names.
encode_path_segment: percent-encodes all non-alphanumeric chars,
used for calendar IDs, file IDs, and message IDs.
validate_resource_name: rejects path traversal (..) and control
chars while preserving intentional / structure, used for Chat
space names, task list IDs, and subscription names. Returns clear
error messages for LLM callers.
* test: add AI edge case tests for URL safety helpers
Cover query/fragment injection, double-encoding, unicode, spaces,
path traversal via encoding, control chars (CR/tab), and clear
error message assertions for LLM callers.
* fix: warn on stderr when API calls fail silently
- Daily briefing calendar events fetch
- Daily briefing tasks fetch
- Daily summary calendar events fetch
- Daily summary unread email count fetch
Addresses PR review feedback about confusing silent failures,
especially for LLM callers that cannot see visual cues.
* fix: harden input validation for AI/LLM callers
- Add src/validate.rs with validate_safe_output_dir, validate_msg_format,
and validate_safe_dir_path helpers
- Validate --output-dir against path traversal in gmail +watch and
events +subscribe
- Validate --msg-format against allowlist in gmail +watch
- Validate --dir against path traversal in script +push
- Add clap value_parser constraint for --msg-format
- Document input validation patterns in AGENTS.md
Closesnpm#23
* chore: add changesets for PR npm#21 commits
* test: add comprehensive test coverage for input validation handlers
* docs: document input validation and URL safety patterns in AGENTS.md and CONTRIBUTING.md
* fix: address PR review comments — reject ?/# in resource names, validate subscription arg, remove redundant validate_msg_format
* fix: store validated PathBuf, remove dead code, delete duplicate SubscribeConfig
Addresses review comments:
- Store validated PathBuf from validate_safe_output_dir instead of
discarding it (output_dir is now Option<PathBuf>)
- Remove duplicate SubscribeConfig from events/mod.rs
- Delete unused validate_msg_format (clap value_parser handles this)
- Remove all #[allow(dead_code)] annotations
* fix: per-segment traversal check in validate_resource_name, fix docs
* fix: harden security validation and deduplicate logic
---------
Co-authored-by: jpoehnelt-bot <jpoehnelt-bot@users.noreply.github.com>
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 5, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 30, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 3, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 25, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 2, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 8, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@dpogue@zkat