Compare commits

..
Author SHA1 Message Date
Abdul WahabandCursor 869c887372 Test: cover directory, chained, and relative /source symlink escapes (#618)
AI assistance: Cursor Grok 4.6 implemented this change.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-22 05:51:12 +05:00
Abdul WahabandCursor d008dd98c3 Fix: stop live-server /source from following symlinks out of the workspace (#618)
AI assistance: Cursor Grok 4.6 implemented this change.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-22 05:19:36 +05:00
4 changed files with 120 additions and 386 deletions
+7 -155
View File
@@ -42,7 +42,6 @@ function shouldRunPageAnalyzers(content, filePath) {
}
const JS_SOURCE_EXTS = new Set(['.js', '.jsx', '.ts', '.tsx', '.mjs', '.cjs']);
const STYLESHEET_EXTS = new Set(['.css', '.scss', '.sass', '.less']);
const REGEX_PREFIX_KEYWORDS = new Set(['await', 'case', 'default', 'delete', 'do', 'else', 'in', 'instanceof', 'new', 'of', 'return', 'throw', 'typeof', 'void', 'yield']);
const BLOCK_BRACE_PREFIX_KEYWORDS = new Set(['do', 'else', 'finally', 'try']);
@@ -257,153 +256,6 @@ function stripCssComments(content) {
return content.replace(/\/\*[\s\S]*?\*\//g, comment => comment.replace(/[^\n]/g, ' '));
}
function blankHtmlComments(text) {
return text.replace(/<!--[\s\S]*?-->/g, comment => comment.replace(/[^\n]/g, ' '));
}
function blankCssLineCommentsInStyleBlocks(text) {
const re = /<style\b[^>]*>([\s\S]*?)<\/style>/gi;
let output = '';
let lastIndex = 0;
let match;
while ((match = re.exec(text)) !== null) {
const inner = match[1];
const openLength = match[0].length - inner.length - '</style>'.length;
output += text.slice(lastIndex, match.index);
output += match[0].slice(0, openLength);
output += blankCssLineComments(inner);
output += match[0].slice(openLength + inner.length);
lastIndex = re.lastIndex;
}
return output + text.slice(lastIndex);
}
function blankHtmlAndCssCommentsOutsideScripts(text) {
const re = /<script\b[^>]*>[\s\S]*?<\/script>/gi;
let output = '';
let lastIndex = 0;
let match;
while ((match = re.exec(text)) !== null) {
output += blankCssLineCommentsInStyleBlocks(stripCssComments(blankHtmlComments(text.slice(lastIndex, match.index))));
output += match[0];
lastIndex = re.lastIndex;
}
return output + blankCssLineCommentsInStyleBlocks(stripCssComments(blankHtmlComments(text.slice(lastIndex))));
}
function blankCssLineComments(text) {
let output = '';
let state = 'code';
let urlDepth = 0;
for (let i = 0; i < text.length; i++) {
const char = text[i];
const next = text[i + 1];
if (state === 'line') {
if (char === '\n') {
output += '\n';
state = 'code';
} else {
output += ' ';
}
continue;
}
if (state === 'single' || state === 'double') {
output += char;
if (char === '\\' && next) {
output += next;
i++;
} else if ((state === 'single' && char === "'") || (state === 'double' && char === '"')) {
state = 'code';
}
continue;
}
const prev = output.length ? output[output.length - 1] : '';
if (char === '/' && next === '/' && urlDepth === 0 && prev !== ':' && prev !== '(' && prev !== '\\') {
output += ' ';
i++;
state = 'line';
continue;
}
if (char === "'") state = 'single';
else if (char === '"') state = 'double';
if (char === '(') {
const behind = output.replace(/\s+$/, '');
if (urlDepth > 0 || /url$/i.test(behind)) urlDepth++;
} else if (char === ')' && urlDepth) {
urlDepth--;
}
output += char;
}
return output;
}
function findAstroFrontmatterClose(text) {
if (!text.startsWith('---')) return -1;
let cursor = text.indexOf('\n');
if (cursor === -1) return -1;
cursor += 1;
while (cursor < text.length) {
if (text[cursor - 1] === '\n' && text.startsWith('---', cursor)) {
let end = cursor + 3;
while (text[end] === ' ' || text[end] === '\t') end++;
if (end >= text.length || text[end] === '\n' || text[end] === '\r') return cursor - 1;
}
const char = text[cursor];
const next = text[cursor + 1];
if (char === "'" || char === '"') {
const close = findQuotedStringEnd(text, cursor, char);
if (close === -1) return -1;
cursor = close + 1;
continue;
}
if (char === '`') {
const close = findTemplateLiteralEnd(text, cursor);
if (close === -1) return -1;
cursor = close + 1;
continue;
}
if (char === '/' && next === '/') {
const lineEnd = text.indexOf('\n', cursor);
if (lineEnd === -1) return -1;
cursor = lineEnd;
continue;
}
if (char === '/' && next === '*') {
const commentEnd = text.indexOf('*/', cursor + 2);
if (commentEnd === -1) return -1;
cursor = commentEnd + 2;
continue;
}
if (char === '/' && next !== '/' && next !== '*') {
const close = findRegexLiteralEnd(text, cursor);
if (close !== -1) {
cursor = close + 1;
continue;
}
}
cursor++;
}
return -1;
}
function blankAstroFrontmatterComments(text) {
const close = findAstroFrontmatterClose(text);
if (close === -1) return text;
return stripJsComments(text.slice(0, close)) + text.slice(close);
}
function blankCommentsForMatchers(text, ext) {
if (PAGE_ANALYZER_EXTS.has(ext)) {
const withFrontmatter = ext === '.astro' ? blankAstroFrontmatterComments(text) : text;
return blankHtmlAndCssCommentsOutsideScripts(withFrontmatter);
}
if (STYLESHEET_EXTS.has(ext)) {
const withoutBlocks = stripCssComments(text);
return ext === '.css' ? withoutBlocks : blankCssLineComments(withoutBlocks);
}
return text;
}
function firstOverusedGoogleFont(text) {
return extractGoogleFontFamilies(text).find(f => OVERUSED_FONTS.has(f)) || '';
}
@@ -1176,13 +1028,14 @@ function detectText(content, filePath, options = {}) {
const ext = extFromFilePath(filePath);
const commentStrippedSource = JS_SOURCE_EXTS.has(ext) ? stripJsComments(content, {
jsx: ext === '.js' || ext === '.jsx' || ext === '.tsx',
}) : blankCommentsForMatchers(content, ext);
}) : content;
const source = stripCssInJsComments(commentStrippedSource, ext);
const lines = source.split('\n');
// Run regex matchers on the full file content (catches Tailwind classes, inline styles)
// Enable block context for CSS files where related properties span multiple lines
findings.push(...runRegexMatchers(lines, filePath, 0, STYLESHEET_EXTS.has(ext) || null, {
const cssLike = new Set(['.css', '.scss', '.sass', '.less']);
findings.push(...runRegexMatchers(lines, filePath, 0, cssLike.has(ext) || null, {
profile,
phase: 'source',
}));
@@ -1197,7 +1050,7 @@ function detectText(content, filePath, options = {}) {
scanCssTextForPseudoStripe(text).map(hit =>
finding(hit.id, filePath, hit.snippet, lineOffset + text.slice(0, hit.index).split('\n').length));
if (STYLESHEET_EXTS.has(ext)) {
if (cssLike.has(ext)) {
findings.push(...scanInsetStripeCss(content, filePath));
findings.push(...pseudoStripeFindings(content, 0));
}
@@ -1225,8 +1078,7 @@ function detectText(content, filePath, options = {}) {
}, () => extractStyleBlocks(content, ext))
: extractStyleBlocks(content, ext);
for (const block of styleBlocks) {
const blockContent = blankCssLineComments(stripCssComments(block.content));
const blockLines = blockContent.split('\n');
const blockLines = block.content.split('\n');
findings.push(...runRegexMatchers(blockLines, filePath, block.startLine - 1, true, {
profile,
phase: 'style-block',
@@ -1237,8 +1089,8 @@ function detectText(content, filePath, options = {}) {
// 1-based, so the offset is startLine - 2; startLine - 1 double-counted and
// reported every selector one line low. runRegexMatchers keeps startLine - 1
// because it indexes its split lines from zero.
findings.push(...scanInsetStripeCss(blockContent, filePath, block.startLine - 2));
findings.push(...pseudoStripeFindings(blockContent, block.startLine - 2));
findings.push(...scanInsetStripeCss(block.content, filePath, block.startLine - 2));
findings.push(...pseudoStripeFindings(block.content, block.startLine - 2));
}
// Extract and scan CSS-in-JS template literals
+15 -7
View File
@@ -936,15 +936,23 @@ function createRequestHandler({ detectScript, liveScriptParts }) {
const filePath = url.searchParams.get('path');
if (!filePath || filePath.includes('..')) { res.writeHead(400); res.end('Bad path'); return; }
const absPath = path.resolve(process.cwd(), filePath);
// Confine to the project root. A bare `startsWith(cwd)` string check lets a
// sibling dir whose name extends the root name (projeto -> projeto-backup)
// slip through; compare on the relative path instead (same pattern as
// sessionFileMetadataFromPollReply below). An empty rel means the request
// resolved to the root directory itself, which this file route never serves.
const rel = path.relative(process.cwd(), absPath);
let realRoot, realTarget;
try {
realRoot = fs.realpathSync(process.cwd());
realTarget = fs.realpathSync(absPath);
} catch {
res.writeHead(404); res.end('File not found'); return;
}
// Confine to the project root after symlink resolution. A bare
// `startsWith(cwd)` string check lets a sibling dir whose name extends the
// root name (projeto -> projeto-backup) slip through; compare on the
// relative path instead (same pattern as sessionFileMetadataFromPollReply
// below). An empty rel means the request resolved to the root directory
// itself, which this file route never serves.
const rel = path.relative(realRoot, realTarget);
if (!rel || rel.startsWith('..') || path.isAbsolute(rel)) { res.writeHead(403); res.end('Forbidden'); return; }
let content;
try { content = fs.readFileSync(absPath, 'utf-8'); }
try { content = fs.readFileSync(realTarget, 'utf-8'); }
catch { res.writeHead(404); res.end('File not found'); return; }
res.writeHead(200, { 'Content-Type': 'text/html; charset=utf-8' });
res.end(content);
-222
View File
@@ -382,228 +382,6 @@ describe('detectText — broken images in source comments', () => {
expect(findings.filter(r => r.antipattern === 'broken-image')).toHaveLength(0);
});
test('ignores img tags in Astro style block comments', () => {
const source = [
'---',
'const title = "Hero";',
'---',
'<style>',
' /*',
' * Example markup: <img src="">',
' */',
' .hero { color: red; }',
'</style>',
].join('\n');
const findings = detectText(source, 'hero.astro');
expect(findings.filter(r => r.antipattern === 'broken-image')).toHaveLength(0);
});
test('ignores img tags in Astro HTML comments', () => {
const source = [
'---',
'const title = "Hero";',
'---',
'<!-- <img src="" alt="Comment-only image" /> -->',
'<img src="/logo.png" alt="Logo" />',
].join('\n');
const findings = detectText(source, 'hero.astro');
expect(findings.filter(r => r.antipattern === 'broken-image')).toHaveLength(0);
});
test('ignores img tags in Astro frontmatter line comments', () => {
const source = [
'---',
'// <img src="" alt="Comment-only image" />',
'const site = "https://example.com";',
'---',
'<img src="/logo.png" alt="Logo" />',
].join('\n');
const findings = detectText(source, 'hero.astro');
expect(findings.filter(r => r.antipattern === 'broken-image')).toHaveLength(0);
});
test('ignores img tags in CSS block comments', () => {
const source = [
'/*',
' * Example markup: <img src="">',
' */',
'.hero { color: red; }',
].join('\n');
const findings = detectText(source, 'hero.css');
expect(findings.filter(r => r.antipattern === 'broken-image')).toHaveLength(0);
});
test('still detects real img tags after an HTML comment in Astro', () => {
const source = [
'---',
'const title = "Hero";',
'---',
'<!-- decorative only -->',
'<img src="" alt="Empty source" />',
].join('\n');
const findings = detectText(source, 'hero.astro');
const broken = findings.filter(r => r.antipattern === 'broken-image');
expect(broken).toHaveLength(1);
expect(broken[0].line).toBe(5);
});
test('does not blank https URLs in Astro frontmatter', () => {
const source = [
'---',
'const site = "https://example.com/logo.png";',
'---',
'<img src="" alt="Empty source" />',
].join('\n');
const findings = detectText(source, 'hero.astro');
expect(findings.filter(r => r.antipattern === 'broken-image')).toHaveLength(1);
});
test('keeps same-line img visible after a bare https URL in Astro markup', () => {
const source = '<p>https://example.com <img src="" alt="Empty source" /></p>';
const findings = detectText(source, 'hero.astro');
expect(findings.filter(r => r.antipattern === 'broken-image')).toHaveLength(1);
});
test('preserves line numbers after comment blanking in Astro', () => {
const source = [
'---',
'const title = "Hero";',
'---',
'<!-- <img src="" alt="Comment-only image" /> -->',
'<p>Intro copy</p>',
'<img src="" alt="Empty source" />',
].join('\n');
const findings = detectText(source, 'hero.astro');
const broken = findings.filter(r => r.antipattern === 'broken-image');
expect(broken).toHaveLength(1);
expect(broken[0].line).toBe(6);
});
test('does not treat comment markers inside script strings as markup comments', () => {
const htmlDelimiters = [
'<script>const open = "<!--";</script>',
'<img>',
'<script>const close = "-->";</script>',
].join('\n');
const cssDelimiters = [
'<script>const open = "/*";</script>',
'<img>',
'<script>const close = "*/";</script>',
].join('\n');
for (const filePath of ['hero.astro', 'hero.vue', 'hero.svelte']) {
expect(detectText(htmlDelimiters, filePath).filter(r => r.antipattern === 'broken-image')).toHaveLength(1);
expect(detectText(cssDelimiters, filePath).filter(r => r.antipattern === 'broken-image')).toHaveLength(1);
}
});
test('ignores preprocessor line comments in stylesheets', () => {
const source = '// font-family: Inter\n.hero { color: red; }';
for (const filePath of ['hero.scss', 'hero.sass', 'hero.less']) {
expect(detectText(source, filePath).filter(r => r.antipattern === 'overused-font')).toHaveLength(0);
}
});
test('still detects live font-family after a preprocessor line comment', () => {
const source = '// skip this\n.hero { font-family: Inter; }';
const findings = detectText(source, 'hero.scss').filter(r => r.antipattern === 'overused-font');
expect(findings).toHaveLength(1);
expect(findings[0].line).toBe(2);
});
test('does not blank https URLs in SCSS', () => {
const source = '.hero { background: url(https://example.com/i.png); }\n.hero { font-family: Inter; }';
const findings = detectText(source, 'hero.scss').filter(r => r.antipattern === 'overused-font');
expect(findings).toHaveLength(1);
expect(findings[0].line).toBe(2);
});
test('ignores frontmatter comments after a --- line inside a template literal', () => {
const source = [
'---',
'const md = `',
'---',
'`;',
'// <img src="" alt="Comment-only image" />',
'---',
'<div>ok</div>',
].join('\n');
expect(detectText(source, 'hero.astro').filter(r => r.antipattern === 'broken-image')).toHaveLength(0);
});
test('ignores preprocessor line comments in component style blocks', () => {
const source = [
'<style lang="scss">',
'// font-family: Inter',
'.hero { color: red; }',
'</style>',
].join('\n');
for (const filePath of ['hero.astro', 'hero.vue', 'hero.svelte']) {
expect(detectText(source, filePath).filter(r => r.antipattern === 'overused-font')).toHaveLength(0);
}
});
test('still detects live font-family after a style-block line comment', () => {
const source = [
'<style lang="scss">',
'// skip this',
'.hero { font-family: Inter; }',
'</style>',
].join('\n');
const findings = detectText(source, 'hero.vue').filter(r => r.antipattern === 'overused-font');
expect(findings).toHaveLength(1);
expect(findings[0].line).toBe(3);
});
test('ignores frontmatter comments after a regex literal that contains quotes', () => {
const source = [
'---',
'const re = /["\']/;',
'// <img src="" alt="Comment-only image" />',
'---',
'<div>ok</div>',
].join('\n');
expect(detectText(source, 'hero.astro').filter(r => r.antipattern === 'broken-image')).toHaveLength(0);
});
test('keeps live font-family after a protocol-relative URL in SCSS', () => {
const sources = [
'.hero { background: url( //cdn.example.com/i.png); font-family: Inter; }',
'.hero { background: url(#{$prefix}//cdn.example.com/i.png); font-family: Inter; }',
];
for (const source of sources) {
expect(detectText(source, 'hero.scss').filter(r => r.antipattern === 'overused-font')).toHaveLength(1);
}
expect(detectText(
'.hero { background: url(@{prefix}//cdn.example.com/i.png); font-family: Inter; }',
'hero.less',
).filter(r => r.antipattern === 'overused-font')).toHaveLength(1);
});
});
describe('detectText — CSS borders', () => {
+98 -2
View File
@@ -5,8 +5,8 @@
import { describe, it, before, after } from 'node:test';
import assert from 'node:assert/strict';
import { existsSync, mkdtempSync, readFileSync, writeFileSync, mkdirSync, rmSync, realpathSync } from 'node:fs';
import { join } from 'node:path';
import { existsSync, mkdtempSync, readFileSync, writeFileSync, mkdirSync, rmSync, realpathSync, symlinkSync } from 'node:fs';
import { join, relative } from 'node:path';
import { tmpdir } from 'node:os';
import { execFileSync, execSync, spawn } from 'node:child_process';
import {
@@ -3319,6 +3319,102 @@ colors: {}
}
});
it('/source rejects a symlink that points outside the project root', async () => {
const outsideDir = mkdtempSync(join(tmpdir(), 'impeccable-live-outside-'));
const outsideFile = join(outsideDir, 'secret.txt');
writeFileSync(outsideFile, 'OUTSIDE SECRET');
const linkPath = join(serverCwd, 'linked.txt');
symlinkSync(outsideFile, linkPath);
try {
const res = await fetch(`http://localhost:${server.port}/source?token=${server.token}&path=linked.txt`);
await res.text().catch(() => {});
assert.equal(res.status, 403);
} finally {
rmSync(linkPath, { force: true });
rmSync(outsideDir, { recursive: true, force: true });
}
});
it('/source serves a symlink whose target stays inside the project', async () => {
const nestedDir = join(serverCwd, 'alias');
mkdirSync(nestedDir, { recursive: true });
const realFile = join(nestedDir, 'page.html');
writeFileSync(realFile, '<h1>via alias</h1>\n');
const linkPath = join(serverCwd, 'alias-link.html');
symlinkSync(realFile, linkPath);
try {
const res = await fetch(`http://localhost:${server.port}/source?token=${server.token}&path=alias-link.html`);
assert.equal(res.status, 200);
const text = await res.text();
assert.ok(text.includes('via alias'));
} finally {
rmSync(linkPath, { force: true });
rmSync(nestedDir, { recursive: true, force: true });
}
});
it('/source returns 404 for a broken symlink', async () => {
const linkPath = join(serverCwd, 'broken-link.txt');
symlinkSync(join(serverCwd, 'missing-target.txt'), linkPath);
try {
const res = await fetch(`http://localhost:${server.port}/source?token=${server.token}&path=broken-link.txt`);
await res.text().catch(() => {});
assert.equal(res.status, 404);
} finally {
rmSync(linkPath, { force: true });
}
});
it('/source rejects a directory symlink whose nested file is outside the project', async () => {
const outsideDir = mkdtempSync(join(tmpdir(), 'impeccable-live-outside-dir-'));
writeFileSync(join(outsideDir, 'cred.txt'), 'OUTSIDE SECRET');
const linkPath = join(serverCwd, 'escape-dir');
symlinkSync(outsideDir, linkPath);
try {
const res = await fetch(`http://localhost:${server.port}/source?token=${server.token}&path=escape-dir/cred.txt`);
await res.text().catch(() => {});
assert.equal(res.status, 403);
} finally {
rmSync(linkPath, { force: true });
rmSync(outsideDir, { recursive: true, force: true });
}
});
it('/source rejects a chained symlink that resolves outside the project', async () => {
const outsideDir = mkdtempSync(join(tmpdir(), 'impeccable-live-outside-chain-'));
const outsideFile = join(outsideDir, 'secret.txt');
writeFileSync(outsideFile, 'OUTSIDE SECRET');
const midPath = join(serverCwd, 'mid-link.txt');
const linkPath = join(serverCwd, 'double-out.txt');
symlinkSync(outsideFile, midPath);
symlinkSync(midPath, linkPath);
try {
const res = await fetch(`http://localhost:${server.port}/source?token=${server.token}&path=double-out.txt`);
await res.text().catch(() => {});
assert.equal(res.status, 403);
} finally {
rmSync(linkPath, { force: true });
rmSync(midPath, { force: true });
rmSync(outsideDir, { recursive: true, force: true });
}
});
it('/source rejects a relative symlink that points outside the project', async () => {
const outsideDir = mkdtempSync(join(tmpdir(), 'impeccable-live-outside-rel-'));
const outsideFile = join(outsideDir, 'secret.txt');
writeFileSync(outsideFile, 'OUTSIDE SECRET');
const linkPath = join(serverCwd, 'rel-out.txt');
symlinkSync(relative(serverCwd, outsideFile), linkPath);
try {
const res = await fetch(`http://localhost:${server.port}/source?token=${server.token}&path=rel-out.txt`);
await res.text().catch(() => {});
assert.equal(res.status, 403);
} finally {
rmSync(linkPath, { force: true });
rmSync(outsideDir, { recursive: true, force: true });
}
});
it('/modern-screenshot.js serves the vendored UMD build', async () => {
const res = await fetch(`http://localhost:${server.port}/modern-screenshot.js`);
assert.equal(res.status, 200);