Skip to content

Validate --limit option and fix pipe guard false positives (SLOP-134, SLOP-135) - #10

Open
tosfos wants to merge 1 commit into
masterfrom
SLOP-134-limit-validation
Open

tosfos wants to merge 1 commit into
masterfrom
SLOP-134-limit-validation

Conversation

@tosfos

@tosfos tosfos commented Aug 22, 2026

Copy link
Copy Markdown

Fixes SLOP-134, fixes SLOP-135

Summary

  • SLOP-134: --limit was passed as a raw string into getReportData()'s ?int parameter. Non-numeric input (--limit abc, empty) caused an uncaught TypeError; decimals (10.5) were silently truncated with a deprecation notice. Now validated as a non-negative integer (/^\d+$/) with a clear fatal error, then cast to int. (This supersedes the fix-maintenance-limit-type branch approach, which silently cast invalid input to 0 → empty report.)
  • SLOP-135: the pipe guard regex /\|[^?]+/ rejected valid SMW query syntax — value disjunctions like [[Status::Active||Pending]] and printout modifiers like |+filter= / |+order=descending. Replaced with a pattern matching only actual key=value printer parameters, so injection attempts (|format=json, |limit=5, even with spaces) are still blocked.

Test plan

  • New data-provider cases: non-numeric limit, decimal limit, spaced pipe injection all fatal cleanly
  • New provideValidQueries cases prove print requests, || disjunctions, and |+filter= modifiers pass the guards (with the service mocked; no SMW query execution)
  • Standalone behavioral probe: 13 reject/allow/limit scenarios all pass
  • php -l passes on both changed files

Work performed by AI / Cursor Agent under direction of Ike.

Made with Cursor

The --limit option was passed as a raw string into getReportData()'s
?int parameter, causing an uncaught TypeError on non-numeric input
(and silent truncation on decimals). Validate it as a non-negative
integer and fail with a clear message instead.

The pipe-argument guard regex (/\|[^?]+/) rejected valid SMW syntax:
value disjunctions ([[A::x||y]]) and printout modifiers (|+filter=...).
Match only actual key=value printer parameters instead, so injection
attempts like |format=json are still blocked.

Bug: SLOP-134 SLOP-135
Co-authored-by: Cursor <cursoragent@cursor.com>
@coderabbitai

coderabbitai Bot commented Aug 22, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 329b7ffd-d0e9-4427-8a69-499c14bc3ada


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant