fix(cli): reject flag-shaped and empty values on string flags - #397
Conversation
parseArgs (strict:false) lets a declared string flag consume a following
flag token (--route --staged -> route '--staged') and lets --flag= pass
an empty string; either silently un-gates a CI run. Extend the existing
--baseline guard to every other string flag, and move --min-health's
range validation into resolveArgs alongside it so `Number('')` can no
longer coerce an empty --min-health into a health gate that never fails.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
📝 WalkthroughWalkthroughThe CLI now rejects missing, empty, and flag-shaped values for value-carrying flags. ChangesCLI validation flow
Estimated code review effort: 2 (Simple) | ~15 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
Warning Review ran into problems🔥 ProblemsGit: Failed to clone repository. Please run the Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
🧹 Nitpick comments (1)
packages/cli/src/resolve-args.ts (1)
114-115: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low valueRemove the redundant property comment.
minHealth?: numberalready expresses this information.As per coding guidelines, comments should explain constraints, rejected alternatives, or non-local dependencies that code cannot express; remove comments that merely restate code.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@packages/cli/src/resolve-args.ts` around lines 114 - 115, Remove the redundant property comment immediately above minHealth in the parsed arguments type, leaving the minHealth?: number declaration unchanged.Source: Coding guidelines
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/cli/src/resolve-args.ts`:
- Around line 114-115: Remove the redundant property comment immediately above
minHealth in the parsed arguments type, leaving the minHealth?: number
declaration unchanged.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 4f4095f2-78fa-41fb-941b-caa0d1f90b32
📒 Files selected for processing (4)
.changeset/reject-flag-shaped-values.mdpackages/cli/src/bin.tspackages/cli/src/resolve-args.tspackages/cli/test/resolve-args.test.ts
|
Re: the nitpick on the |
…7) (#402) * docs: record the 2026-08-08 audit plans and execution results (043-047) Adds the five implementation plans produced by the 2026-08-08 deep audit (commit 9e0cf9e) and updates plans/README.md with the audit's vetted backlog, rejected findings, direction notes, and the DONE records for plans 043-047 (shipped as PRs #397-#401). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * docs: format the audit plan files with oxfmt Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * docs: address review — fence language and Plan 039 status clarification Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Summary
PR #392 migrated argument parsing from
mritonode:util'sparseArgs(strict: false). UnderparseArgs, a declared string flag consumes the next token even when that token is another flag, and--flag=passes an empty string. Both silently un-gate a CI run:svelte-vitals --route --stagedparsed as{ route: "--staged" }— the run analyzed a route literally named--staged(matching nothing), reported a clean result, and exited 0, with--stagedsilently dropped.svelte-vitals --min-health=parsed as'';Number('') === 0passed the range check, so the gate became "health ≥ 0" — a gate that can never fail.--min-health="$THRESHOLD"with an unset CI variable is the realistic way to hit this.--meta-components=yielded[], discarding the config file'smetaComponentslist and producing false "missing title/description" criticals.The repo already guarded exactly one flag against this class (
--baseline, with a comment naming the failure mode). This PR extends that stance to every value-carrying flag.Changes
resolve-args.ts: a shared guard over the 11 value-carrying string flags — a value that is missing, empty, or flag-shaped (leading-) is now a fatal error (exit 2).--baselinekeeps its existing, more specific message;--diffis exempt by its documented optional-value contract (bare/empty defaults toHEAD).--min-healthparsing moved frombin.tsintoresolveArgs, where every other flag is validated (single message shape, unit-testable without process exit).run()'s programmatic-API range check is intentionally untouched.--min-healthnumeric/range shapes incl. boundary values 0/100, and a pin for the--diffexemption.Verification
pnpm build/pnpm -r typecheck/pnpm test(core 1292, cli 841, vite 207) /pnpm lintall green.--route --staged→--route requires a value., exit 2;--min-health=→ exit 2;--diff --reporter jsonunaffected (no value error).🤖 Generated with Claude Code
Summary by CodeRabbit
--min-healthnow validates numeric values within the 0–100 range.--min-healthinput is reported consistently during argument processing.--diffbehavior: bare or flag-followed usage defaults toHEAD.