fix(xdev): tolerated malformed inline-device allowlist config

Settings.get returns raw merged config without element validation, so a
scalar or non-string tools.xdevInlineDevices entry reached Bun.Glob and
threw while building the system prompt. Normalized the allowlist to
string patterns and compiled globs once per render.
This commit is contained in:
can1357
2026-07-24 01:24:20 +02:00
parent f4641c165e
commit 041adb2b1f
2 changed files with 26 additions and 6 deletions
@@ -258,6 +258,14 @@ describe("read and write route xd:// device URLs", () => {
const catalogWithAllowlistDocs = registry.docsAll("catalog", ["mcp__context_mode_*"]);
expect(catalogWithAllowlistDocs).not.toContain("## mcp__context_mode_ctx_execute");
// Malformed user config (scalar or non-string entries reach the
// registry unvalidated) degrades to the catalog listing instead of
// throwing while the system prompt is built.
const scalarAllowlistDocs = registry.docsAll("builtins", "mcp__context_mode_*" as never);
expect(scalarAllowlistDocs).toContain("- xd://mcp__context_mode_ctx_execute —");
const nonStringAllowlistDocs = registry.docsAll("builtins", [123] as never);
expect(nonStringAllowlistDocs).toContain("- xd://mcp__context_mode_ctx_execute —");
} finally {
await removeWithRetries(tempDir);
}