fix(write): rejected unknown uri-like targets

- Blocked malformed and unregistered URI-like paths before filesystem resolution.
- Suggested canonical xd:// spelling while preserving explicitly escaped local paths.
- Added regression coverage for xdt://, xd:/, and xd/ near misses.

Fixes #6123
This commit is contained in:
roboomp
2026-07-21 21:19:27 +00:00
parent 39c95e5e29
commit ea5c816e65
4 changed files with 59 additions and 5 deletions
@@ -86,6 +86,32 @@ describe("read and write route xd:// device URLs", () => {
}
});
it("rejects near-miss xd addresses before filesystem fallback", async () => {
const tempDir = await fs.mkdtemp(path.join(os.tmpdir(), "write-xdev-near-miss-"));
try {
const tools = await createTools(xdevSession(tempDir));
const write = tools.find(entry => entry.name === "write");
expect(write).toBeDefined();
for (const target of ["xdt://web_search", "xd:/web_search", "xd/web_search"]) {
await expect(write!.execute(`write-${target}`, { path: target, content: "{}" })).rejects.toThrow(
"Did you mean 'xd://web_search'?",
);
}
expect(await Bun.file(path.join(tempDir, "xdt:/web_search")).exists()).toBe(false);
expect(await Bun.file(path.join(tempDir, "xd/web_search")).exists()).toBe(false);
const escaped = await write!.execute("write-explicit-path", {
path: "./xd/web_search",
content: "intentional file",
});
expect(escaped.isError).toBeUndefined();
expect(await Bun.file(path.join(tempDir, "xd/web_search")).text()).toBe("intentional file");
} finally {
await removeWithRetries(tempDir);
}
});
it("resolves function-valued device approvals per payload and fails closed on bad content", async () => {
const tempDir = await fs.mkdtemp(path.join(os.tmpdir(), "write-xdev-approval-"));
try {