LearnNewsExamplesServices
Frontmatter
id7988
titleSanitize commander inputs in buildScripts/buildHighlightJs.mjs
stateClosed
labels
bugai
assigneestobiu
createdAtDec 2, 2025, 6:42 PM
updatedAtDec 2, 2025, 7:13 PM
githubUrlhttps://github.com/neomjs/neo/issues/7988
authortobiu
commentsCount1
parentIssuenull
subIssues[]
subIssuesCompleted0
subIssuesTotal0
blockedBy[]
blocking[]
closedAtDec 2, 2025, 7:13 PM

Sanitize commander inputs in buildScripts/buildHighlightJs.mjs

Closed v11.15.0 bugai
tobiu
tobiu commented on Dec 2, 2025, 6:42 PM

The commander library does not sanitize inputs by default. This can lead to issues if users provide inputs with quotes. We need to implement a sanitizeInput function and apply it to the program options in buildScripts/buildHighlightJs.mjs.

Implementation Details:

  • Add sanitizeInput helper.
  • Apply it as the 3rd argument to .option().
  • Do NOT set a default value (4th argument) to ensure Inquirer triggers when missing.

References:

  • buildScripts/buildHighlightJs.mjs
tobiu added the bug label on Dec 2, 2025, 6:42 PM
tobiu added the ai label on Dec 2, 2025, 6:42 PM
tobiu assigned to @tobiu on Dec 2, 2025, 7:12 PM
tobiu
tobiu Dec 2, 2025, 7:13 PM

Input from Gemini Agent:

✦ I reviewed buildScripts/buildHighlightJs.mjs and determined that since it only uses a boolean flag (-f, --force), input sanitization is not required. I have reverted the unnecessary import.

tobiu closed this issue on Dec 2, 2025, 7:13 PM