mirror of
https://gitea.com/gitea/tea.git
synced 2026-09-10 07:26:33 -04:00
Comma-separated flags (`--assignees`, `--labels`, `--add/remove-labels`,
`--add/remove-reviewers`, `--events`, login `--scopes`) silently accepted
stray commas and whitespace, producing values like `[""]` for empty input
or `["alice", "", "bob"]` for `--assignees=alice,,bob`. Those blanks
were then forwarded to the Gitea SDK, where they either triggered obscure
server errors or silently mutated state in unexpected ways.
Root cause: a mix of `strings.Split(s, ",")` and ad-hoc trim loops, none
of which rejected empty segments.
Introduce `modules/utils.SplitCSV` as the single parser for all CSV flag
values. It:
- returns `nil` for an empty or whitespace-only input (so callers can use
`len(x) == 0` to mean "not set", and `cmd.IsSet("...")` keeps
working),
- drops empty and whitespace-only segments anywhere in the input,
- otherwise trims surrounding whitespace from each remaining segment.
`cmd/flags.SplitCSV` is re-exported from `cmd/flags/csvflag.go` so
existing call sites read `flags.SplitCSV` without depending on a leaf
package that `modules/task` already imports them.
Convert the remaining raw `strings.Split(..., ",")` sites:
- `cmd/flags/issue_pr.go` (issue/pr --assignees, --labels and the
set/add/remove variants)
- `cmd/pulls/edit.go` (`--add-reviewers`, `--remove-reviewers`)
- `cmd/webhooks/create.go`, `cmd/webhooks/update.go` (`--events`)
- `modules/task/login_create.go` (login `--scopes`)
Drop the now-unused `"strings"` imports from the three cmd/* files.
Tests:
- `modules/utils/splitcsv_test.go` — table-driven coverage for empty,
whitespace-only, leading/trailing commas, internal empty segments,
surrounding whitespace, and re-imported identity with `flags.SplitCSV`.
- `cmd/flags/csvflag_test.go` — `GetValues` happy path, error path,
empty entry drop, and AvailableFields variants.
- `cmd/flags/issue_pr_test.go` — regression test for
`GetIssuePREditFlags` proving `SetAssignees/AddAssignees/...`
produce `nil` (not `[""]`) for empty input and trimmed slices for
mixed inputs.
49 lines
1.6 KiB
Go
49 lines
1.6 KiB
Go
// Copyright 2026 The Gitea Authors. All rights reserved.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package utils
|
|
|
|
import (
|
|
"reflect"
|
|
"testing"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
)
|
|
|
|
func TestSplitCSV(t *testing.T) {
|
|
cases := []struct {
|
|
name string
|
|
in string
|
|
want []string
|
|
}{
|
|
{name: "empty", in: "", want: nil},
|
|
{name: "single", in: "alice", want: []string{"alice"}},
|
|
{name: "two", in: "alice,bob", want: []string{"alice", "bob"}},
|
|
{name: "trailing comma", in: "alice,bob,", want: []string{"alice", "bob"}},
|
|
{name: "leading comma", in: ",alice,bob", want: []string{"alice", "bob"}},
|
|
{name: "double comma", in: "alice,,bob", want: []string{"alice", "bob"}},
|
|
{name: "only commas", in: ",,,", want: nil},
|
|
{name: "whitespace around entries trimmed", in: " alice , bob ", want: []string{"alice", "bob"}},
|
|
{name: "whitespace-only entries dropped", in: "alice, ,bob", want: []string{"alice", "bob"}},
|
|
{name: "tabs and newlines trimmed", in: "\talice\n,\t\nbob", want: []string{"alice", "bob"}},
|
|
}
|
|
for _, tc := range cases {
|
|
t.Run(tc.name, func(t *testing.T) {
|
|
got := SplitCSV(tc.in)
|
|
if !reflect.DeepEqual(got, tc.want) {
|
|
t.Errorf("SplitCSV(%q) = %#v, want %#v", tc.in, got, tc.want)
|
|
}
|
|
})
|
|
}
|
|
}
|
|
|
|
func TestSplitCSVEmptyReturnsNilNotEmptySlice(t *testing.T) {
|
|
// Regression: previously GetValues returned []string{""} for empty
|
|
// input, which confused length-based "is this flag set?" checks at
|
|
// every call site. nil round-trips cleanly through encoding/json.
|
|
got := SplitCSV("")
|
|
assert.Nil(t, got)
|
|
got = SplitCSV(",,,")
|
|
assert.Nil(t, got)
|
|
}
|