fix(core): enforce external ref path casing#2861
Closed
popsiclelmlm wants to merge 1 commit into
Closed
Conversation
🦋 Changeset detectedLatest commit: c407edb The changes in this PR will be included in the next version bump. This PR includes changesets to release 3 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What/Why/How?
Summary
Fixes #1326 by making local external ref resolution reject file paths whose casing does not match the filesystem entry.
Reproduction
On case-insensitive filesystems, a ref such as
./externalInfo.yamlcan resolve successfully even when the real file is namedexternalinfo.yaml. That means rules such asno-unresolved-refsmay accept refs that fail on case-sensitive environments.The added regression test simulates this by making the filesystem report
externalinfo.yamlwhile the resolver tries to loadexternalInfo.yaml.Root cause
BaseResolver.loadExternalRefresolved local paths withpath.resolve, then calledlstatSyncandreadFile. On a case-insensitive filesystem those calls still succeed for a mismatched filename, so the resolver never observed the casing mismatch.Changes
@redocly/openapi-coreand@redocly/cli.Reference
Fixes #1326
Testing
git diff --checkVITEST_SUITE=unit ./node_modules/.bin/vitest run packages/core/src/__tests__/resolve.test.ts --coverage.enabled=falsenpm run compilenpm run typechecknpm run lint(0 errors; existing warnings remain)npm run format:checkScreenshots (optional)
N/A
Check yourself
Security