mirror of
https://github.com/ever-co/ever-gauzy.git
synced 2026-10-02 01:54:50 +08:00
Static analysis on the pull request flagged two genuine security problems in paths that handle untrusted content, plus a batch of accessibility defects. - The neutralizer that fences document text before it reaches an AI prompt used a pattern vulnerable to exponential backtracking. Since it runs over uploaded content, a crafted document could pin a request thread. The pattern no longer backtracks, with a test that asserts a pathological input completes promptly and is still neutralized. - Two render paths bypassed the framework sanitizer while displaying document content, which is attacker-controlled by definition: an uploaded HTML file or a page authored by someone else. Both now sanitize before rendering, covered by tests for script tags, event-handler attributes and javascript: URLs. - Form controls across the filter bar, bulk bar, saved views, share dialog and the editor now carry associated labels. - Reduced the complexity of the chunker, block splitter and upload service by extracting helpers. Behavior is unchanged: the chunker refactor was validated by a differential harness over ~9,900 comparisons, and the upload refactor by 43 scenarios comparing both results and ordered side effects, each checked against deliberately broken variants to prove the harness detects breakage. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
76 lines
3.9 KiB
Properties
76 lines
3.9 KiB
Properties
# =============================================================================
|
|
# SonarQube/SonarCloud Configuration for Ever Gauzy
|
|
# =============================================================================
|
|
|
|
# Project Identification
|
|
sonar.projectKey=ever-co_ever-gauzy
|
|
sonar.projectName=Ever Gauzy
|
|
sonar.projectVersion=0.1.0
|
|
sonar.sourceEncoding=UTF-8
|
|
|
|
# Organization (required for SonarCloud)
|
|
sonar.organization=ever-co
|
|
|
|
# =============================================================================
|
|
# Source Configuration
|
|
# =============================================================================
|
|
|
|
# Monorepo source directories (only existing top-level folders)
|
|
sonar.sources=apps,packages,.scripts,tools
|
|
|
|
# Test directories (same as sources - tests are co-located)
|
|
sonar.tests=apps,packages
|
|
|
|
# Test file patterns (TypeScript/JavaScript test files). `**/*.steps.ts` are the playwright-bdd step
|
|
# definitions — test code, classified like the specs they replaced (not main source).
|
|
sonar.test.inclusions=**/*.spec.ts,**/*.test.ts,**/*.spec.tsx,**/*.test.tsx,**/*.e2e-spec.ts,**/*.steps.ts
|
|
|
|
# =============================================================================
|
|
# Exclusions
|
|
# =============================================================================
|
|
|
|
# Exclude dependencies, build outputs, and generated files.
|
|
#
|
|
# `_katex.scss` is vendored, minified, third-party CSS: it is `katex@0.16.47`'s own
|
|
# `dist/katex.min.css` with only the font URLs rewritten, regenerated by
|
|
# `packages/plugins/docs-ui/tools/generate-katex-css.js` and marked "DO NOT EDIT BY HAND".
|
|
# Analyzing it reported 24 "missing generic font family" bugs plus a duplicate `.katex svg`
|
|
# selector — all upstream KaTeX's, none fixable here: hand-edits would be wiped by the next
|
|
# regeneration and would diverge this copy from upstream. It matches the spirit of the
|
|
# `**/*.min.css` exclusion already above and only misses it because of the `.scss` suffix.
|
|
sonar.exclusions=**/node_modules/**,**/dist/**,**/build/**,**/out/**,**/.angular/**,**/.nx/**,**/.cache/**,**/coverage/**,**/tmp/**,**/*.d.ts,**/*.min.js,**/*.min.css,**/assets/**,**/public/**,**/*.json,**/*.md,**/docs-ui/src/lib/editor/styles/_katex.scss
|
|
|
|
# Exclude test files from coverage analysis (they are analyzed as tests)
|
|
sonar.coverage.exclusions=**/*.spec.ts,**/*.test.ts,**/*.spec.tsx,**/*.test.tsx,**/*.e2e-spec.ts,**/test/**,**/tests/**,**/e2e/**,**/__mocks__/**,**/__tests__/**
|
|
|
|
# Exclude files from duplication detection. The whole gauzy-e2e project is test code, and the
|
|
# playwright-bdd step files (`**/*.steps.ts`) intentionally repeat similar page-object call sequences
|
|
# 1:1 from the specs they replaced — copy-paste detection there is noise (the old `*.spec.ts` were
|
|
# already excluded for the same reason).
|
|
sonar.cpd.exclusions=**/*.spec.ts,**/*.test.ts,**/*.steps.ts,apps/gauzy-e2e/**,**/migrations/**,**/fixtures/**,**/*.mock.ts
|
|
|
|
# =============================================================================
|
|
# Coverage Configuration
|
|
# =============================================================================
|
|
|
|
# LCOV coverage report paths (Jest generates these)
|
|
sonar.javascript.lcov.reportPaths=coverage/lcov.info,coverage/**/lcov.info,apps/**/coverage/lcov.info,packages/**/coverage/lcov.info
|
|
|
|
# =============================================================================
|
|
# TypeScript Configuration
|
|
# =============================================================================
|
|
|
|
# TypeScript configuration file for type resolution
|
|
sonar.typescript.tsconfigPath=tsconfig.base.json
|
|
|
|
# =============================================================================
|
|
# Language-specific Settings
|
|
# =============================================================================
|
|
|
|
# Set the main language to TypeScript
|
|
sonar.language=ts
|
|
|
|
# File suffixes for TypeScript and JavaScript analysis
|
|
sonar.typescript.file.suffixes=.ts,.tsx
|
|
sonar.javascript.file.suffixes=.js,.jsx,.mjs,.cjs
|