Harden audit findings: correctness, type-safety, Windows conventions & polish

Audit-pass over CODE-AUDIT.md (~48 items closed this pass; all verified —
typecheck + 234 tests + eslint + prettier green).

Correctness / bugs:
- B3: match the release checksum to the asset's filename line (no wrong-hash verify)
- B4: newline-safe metadata probe (one --print with a unit-separator delimiter)
- B5 / L88: guard the meta event against canceled items; progress no longer promotes
  a queued item outside pump()
- B7: cookie-login promise always resolves (handles destroy-without-close)
- L146: trim parser rejects >2 colon-group times; M36: Library selection counts only
  actionable rows
- L11 / L50 / L156 / L57 / L159 / L15 / L3: live queue count, empty-cookie message,
  schedule picker min, dead-code/comment cleanup

Type safety:
- Enable noUncheckedIndexedAccess + noFallthroughCasesInSwitch (15 real edge cases fixed)

Resilience / Windows / metadata:
- R5: settings write failure handled (no unhandled IPC rejection; reconciles to truth)
- W1 / W5 / W6: min window size, seeded folder picker, parented sign-in window;
  L147 dead macOS branches removed
- CL1: shared stdout markers; package/builder metadata (license, homepage, repository,
  copyright, tsbuildinfo glob)

Copy / docs / tests:
- M37 / SR9 dev-jargon cleanup in hints; M8 / M25 / M26 / L66 / L80 / L81 reconciled
- New unit tests for L35 (isValidMediaItem) and L36 (compareVersions)

This commit also checkpoints the previously-uncommitted feat/tray-background-clipboard
work it builds on: background running + auto-download, library clipboard detection,
tray, binary management & library scale, credential encryption at rest, the shared
jsonStore and ui/ primitives, and the eslint/prettier tooling.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-06-30 13:02:54 -04:00
parent a6a8c5f578
commit 1376c2dee8
82 changed files with 4571 additions and 1276 deletions
+52 -2
View File
@@ -5,9 +5,10 @@ import {
isValidHistoryEntry,
isValidErrorLogEntry,
isTemplateLike,
isValidSource
isValidSource,
isValidMediaItem
} from '../src/main/validation'
import type { HistoryEntry, ErrorLogEntry, Source } from '@shared/ipc'
import type { HistoryEntry, ErrorLogEntry, Source, MediaItem } from '@shared/ipc'
// --- S4: filename template path-traversal -----------------------------------
@@ -208,3 +209,52 @@ describe('isValidSource', () => {
expect(isValidSource('nope')).toBe(false)
})
})
// --- L35: isValidMediaItem — the persisted media-items.json row validator ----
describe('isValidMediaItem', () => {
const valid: MediaItem = {
id: 'src1:vid1',
sourceId: 'src1',
videoId: 'vid1',
title: 'A video',
url: 'https://youtube.com/watch?v=vid1',
playlistTitle: 'Uploads',
playlistIndex: 1,
downloaded: false
}
it('accepts a minimal valid item', () => {
expect(isValidMediaItem(valid)).toBe(true)
})
it('accepts the optional fields when well-typed', () => {
expect(
isValidMediaItem({
...valid,
durationLabel: '3:21',
downloaded: true,
downloadedAt: 1_700_000_000_000,
filePath: 'C:/Videos/a.mp4'
})
).toBe(true)
})
it('rejects a missing or wrong-typed required field', () => {
const { videoId: _v, ...noVideoId } = valid
expect(isValidMediaItem(noVideoId)).toBe(false)
expect(isValidMediaItem({ ...valid, playlistIndex: '1' })).toBe(false)
expect(isValidMediaItem({ ...valid, downloaded: 'no' })).toBe(false)
})
it('rejects wrong-typed optional fields', () => {
expect(isValidMediaItem({ ...valid, durationLabel: 42 })).toBe(false)
expect(isValidMediaItem({ ...valid, downloadedAt: 'soon' })).toBe(false)
expect(isValidMediaItem({ ...valid, filePath: 99 })).toBe(false)
})
it('rejects non-objects', () => {
expect(isValidMediaItem(null)).toBe(false)
expect(isValidMediaItem('nope')).toBe(false)
})
})