mirror of
https://github.com/larksuite/cli.git
synced 2026-08-03 08:32:46 +08:00
* refactor: add output emitter contract and differential harness Introduce a leaf Emitter in internal/output that composes the existing output primitives (content-safety scan, envelope, jq, format rendering, notice) behind a single command-scoped port. The emitter is unwired: no production caller is migrated, so CLI output stays byte-for-byte unchanged. A differential test harness drives the real legacy entry points (RuntimeContext.Out/OutRaw/OutFormat/..., WriteSuccessEnvelope and the pagination formatter) and asserts byte-identical stdout/stderr plus typed errors, locking behavior before later slices migrate callers. * refactor: tighten emitter API and cover pagination with real tests - split Emitter.Success/PartialFailure and drop EmitOptions.OK so a missing ok flag can no longer silently emit ok:false - give StreamPage its own StreamOptions (format + pretty) instead of reusing EmitOptions, making "jq needs aggregation" a compile-time fact - pin the Emitter jq-error contract (returns error, writes no stderr); the caller adapter re-emits the legacy stderr line on migration - add in-package tests driving the real apiPaginate/servicePaginate over a mock transport: multi-page aggregation, empty-result fallback, MarkRaw handling, and the business-error raw-response red line * test: use standard TestFactory harness for pagination tests Replace the hand-rolled RoundTripper + APIClient construction in the apiPaginate/servicePaginate tests with cmdutil.TestFactory and its httpmock.Registry, and isolate LARKSUITE_CLI_CONFIG_DIR to t.TempDir(), matching the repo's standard HTTP-mocked test convention. Assertions and coverage (multi-page aggregation, empty-result fallback, MarkRaw, and the business-error raw-response red line) are unchanged. * refactor: route success output through the single Emitter port Migrate the success-output surfaces onto internal/output's Emitter, byte-for-byte identical (proven by frozen golden diffs and the real paginate/HandleResponse tests): - RuntimeContext.Out/OutRaw/OutFormat/OutFormatRaw/OutPartialFailure now build an Emitter and call Success/PartialFailure; emit and outFormat are removed. An adapter maps the returned error back to the legacy outputErrOnce / jq-error stderr / exit-code behavior. - WriteSuccessEnvelope degrades to a thin Emitter.Success delegate; its 8 callers are unchanged. - apiPaginate/servicePaginate stream pages via Emitter.StreamPage; the aggregate and business-error raw-response branches are untouched. - HandleResponse routes its non-JSON structured-response branch through Emitter.Success. Frozen golden fixtures replace the runtime legacy oracles so the differential harness cannot go self-referential after migration. * fix: keep _notice on struct payloads in Emitter's unknown-format fallback printLegacyDataJSON now normalizes via toGeneric first (matching FormatValue), so a struct / named-map payload retains its injected _notice on the unknown-format -> JSON fallback rather than dropping it silently. Add a regression test that fails against the pre-fix path. * refactor: make the Emitter own write failures and stop mutating inputs Route every Emitter stdout path through a render-to-buffer-then-copy helper so a marshal/render failure leaves stdout empty and surfaces a typed internal error (with cause), and a stdout write failure is propagated instead of silently swallowed. Leaf writers gain error-returning Write* cores; the legacy Print*/FormatValue wrappers keep their exact behavior for unmigrated callers. - handleEmitterError now captures every error, not only the jq/safety branches; flip OutRaw's write-error test to assert propagation. - Clone the map before injecting _notice so a caller's payload is never mutated and an existing _notice is never overwritten. - Preserve jq's own typed error (validation/api) on a bad expression or runtime failure; only wrap genuine stdout write failures. - Split tests: normative emitter_contract_test.go vs frozen emitter_legacy_compat_test.go (base SHA recorded, self-update env vars removed). * fix: satisfy license-header and forbidigo lint on the emitter changes - Move the base-SHA note below the copyright header in the renamed legacy-compat test so the license-header check sees a valid header at the top. - Route the leaf wrappers' marshal/format stderr messages through a single legacyStderrf helper (one //nolint:forbidigo) instead of bare os.Stderr, preserving exact legacy behavior for unmigrated direct callers while passing forbidigo; drop the now-unused os imports. * fix: stop legacy CSV wrappers reporting write failures to stderr Align FormatAsCSV/FormatAsCSVPaginated and FormatValue/FormatPage's CSV branch with the other leaf wrappers: report only marshal failures, swallow write failures. Previously they emitted a 'csv write error' for the (empty) line and the JSON-fallback write failures that the pre-refactor code ignored, and mislabeled a JSON write failure as a CSV one. Failure-path only; success output is unchanged (golden double-diff still byte-for-byte).
61 lines
1.6 KiB
Go
61 lines
1.6 KiB
Go
// Copyright (c) 2026 Lark Technologies Pte. Ltd.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package output
|
|
|
|
import (
|
|
"errors"
|
|
"fmt"
|
|
"io"
|
|
"strings"
|
|
|
|
"github.com/larksuite/cli/errs"
|
|
extcs "github.com/larksuite/cli/extension/contentsafety"
|
|
)
|
|
|
|
// ScanResult holds the output of ScanForSafety.
|
|
type ScanResult struct {
|
|
Alert *extcs.Alert
|
|
Blocked bool
|
|
BlockErr error
|
|
}
|
|
|
|
// ScanForSafety runs content-safety scanning on the given data.
|
|
// cmdPath is the raw cobra CommandPath().
|
|
// When MODE=off, no provider registered, or the command is not allowlisted,
|
|
// returns a zero ScanResult.
|
|
func ScanForSafety(cmdPath string, data any, errOut io.Writer) ScanResult {
|
|
alert, csErr := runContentSafety(cmdPath, data, errOut)
|
|
if errors.Is(csErr, errBlocked) {
|
|
return ScanResult{
|
|
Alert: alert,
|
|
Blocked: true,
|
|
BlockErr: wrapBlockError(alert),
|
|
}
|
|
}
|
|
return ScanResult{Alert: alert}
|
|
}
|
|
|
|
// wrapBlockError creates a typed error for content-safety block.
|
|
func wrapBlockError(alert *extcs.Alert) error {
|
|
var matchedRules []string
|
|
if alert != nil {
|
|
matchedRules = alert.MatchedRules
|
|
}
|
|
return errs.NewContentSafetyError(errs.SubtypeContentSafety,
|
|
"content safety violation detected (rules: %s)", strings.Join(matchedRules, ", ")).
|
|
WithRules(matchedRules...).
|
|
WithCause(errBlocked)
|
|
}
|
|
|
|
// WriteAlertWarning writes a human-readable content-safety warning to w.
|
|
// Used by non-JSON output paths (pretty, table, csv) in warn mode.
|
|
func WriteAlertWarning(w io.Writer, alert *extcs.Alert) error {
|
|
if alert == nil {
|
|
return nil
|
|
}
|
|
_, err := fmt.Fprintf(w, "warning: content safety alert from %s (rules: %s)\n",
|
|
alert.Provider, strings.Join(alert.MatchedRules, ", "))
|
|
return err
|
|
}
|