mirror of
https://github.com/heygen-com/hyperframes.git
synced 2026-09-11 23:00:03 +00:00
* refactor: make @hyperframes/lint depend only on parsers, not core Relocates the leaf utilities lint pulled from core — URL/asset-path helpers, font aliases, and the slideshow manifest parser — into the standalone @hyperframes/parsers base, and drops @hyperframes/core from lint's dependencies. Core keeps back-compat re-export stubs at the old paths, so producer/studio/cli are unchanged. Why: lint was the lightweight validator from #1749, but depending on core transitively pulled studio-server (hono) and bpm-detective — irrelevant to linting. Now installing @hyperframes/lint pulls only parsers + postcss, and the core<->lint dependency cycle is gone. - parsers main entry stays browser-safe (pure utils only); the node:path asset helpers live behind the new @hyperframes/parsers/asset-paths subpath - slideshow parser exposed via @hyperframes/parsers/slideshow * feat(lint): add browser entry; harden CSS url() regex (ReDoS) @hyperframes/lint/browser — a fully client-side rule engine (lintHyperframeHtml, lintMediaUrls, shouldBlockRender) with zero node: builtins, so browser-only editors can validate compositions with no Node.js and no server round-trip. Closes the browser-validation ask on #1749. - shouldBlockRender extracted from the fs-bound project.ts into its own pure module so the browser entry stays node-free - pure composition primitives (data types, font aliases, URL helper) exposed via a new recast-free @hyperframes/parsers/composition subpath, so the browser bundle tree-shakes out the GSAP/recast machinery (verified: esbuild platform=browser bundles with 0 node builtins) - lint built with a platform:browser tsup pass — compile-time guarantee the browser entry never pulls a node builtin - harden CSS_URL_RE against polynomial ReDoS (CodeQL js/polynomial-redos); behavior-preserving, verified against existing tests + an old/new parity check - parsers/lint marked sideEffects:false
46 lines
1.5 KiB
TypeScript
46 lines
1.5 KiB
TypeScript
/**
|
|
* Shared primitives for scanning and rewriting asset paths in HTML/CSS.
|
|
*
|
|
* Used by: rewriteSubCompPaths (core), collectExternalAssets (producer),
|
|
* localizeExternalAssets (CLI publish).
|
|
*/
|
|
|
|
import { isAbsolute, relative, resolve } from "node:path";
|
|
|
|
/**
|
|
* Regex matching CSS `url(...)` references — captures the quote style and the
|
|
* raw URL. The URL group is anchored to non-whitespace at both ends so the
|
|
* surrounding `\s*` can never overlap it (avoids polynomial-ReDoS backtracking);
|
|
* the captured value is whitespace-bounded already, matching the old behavior
|
|
* after callers `.trim()` it.
|
|
*/
|
|
export const CSS_URL_RE = /\burl\(\s*(["']?)([^)"'\s](?:[^)"']*[^)"'\s])?)\1\s*\)/g;
|
|
|
|
/** Attributes that may contain relative asset paths. */
|
|
export const PATH_ATTRS = ["src", "href"] as const;
|
|
|
|
/** Returns true for URLs/prefixes that should never be rewritten. */
|
|
export function isNonRelativeUrl(val: string): boolean {
|
|
return (
|
|
!val ||
|
|
val.startsWith("http://") ||
|
|
val.startsWith("https://") ||
|
|
val.startsWith("//") ||
|
|
val.startsWith("data:") ||
|
|
val.startsWith("#") ||
|
|
val.startsWith("/")
|
|
);
|
|
}
|
|
|
|
/**
|
|
* Cross-platform containment check: is `childPath` inside `parentPath`?
|
|
* Equality counts as "inside".
|
|
*/
|
|
export function isPathInside(childPath: string, parentPath: string): boolean {
|
|
const absChild = resolve(childPath);
|
|
const absParent = resolve(parentPath);
|
|
if (absChild === absParent) return true;
|
|
const rel = relative(absParent, absChild);
|
|
return rel !== "" && !rel.startsWith("..") && !isAbsolute(rel);
|
|
}
|