fix(vector): address PR review round 12 — bool guard + strict doc_id validation
- _group_int_doc_ids: use type(value) is not int instead of isinstance, since bool is an int subclass and would otherwise stringify to "True"/"False" and corrupt legacy payloads on backfill. - Replace doc_id.isdigit() guards in 5 boundary sites (api/visualization, auth/viz_routes, search/context note/news_item/ deck_card branches) with a shared is_valid_nextcloud_doc_id helper that rejects "0", leading zeros, and Unicode digit classes (superscripts, Arabic-Indic, Devanagari) which pass isdigit() but cannot be valid MySQL AUTO_INCREMENT IDs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.7
parent
f3ce46da0f
commit
f9ad7dc52e
@@ -0,0 +1,54 @@
|
||||
"""Unit tests for shared boundary validators."""
|
||||
|
||||
import pytest
|
||||
|
||||
from nextcloud_mcp_server.utils.validation import is_valid_nextcloud_doc_id
|
||||
|
||||
|
||||
@pytest.mark.unit
|
||||
@pytest.mark.parametrize(
|
||||
"value",
|
||||
[
|
||||
"1",
|
||||
"42",
|
||||
"1234567890",
|
||||
"9999999999999999999",
|
||||
],
|
||||
)
|
||||
def test_accepts_positive_ascii_integers(value):
|
||||
"""Any positive ASCII integer (no leading zero) is a valid doc_id."""
|
||||
assert is_valid_nextcloud_doc_id(value) is True
|
||||
|
||||
|
||||
@pytest.mark.unit
|
||||
@pytest.mark.parametrize(
|
||||
"value,reason",
|
||||
[
|
||||
("", "empty string"),
|
||||
("0", "MySQL AUTO_INCREMENT starts at 1"),
|
||||
("01", "leading zero"),
|
||||
("00", "leading zeros"),
|
||||
("-1", "negative"),
|
||||
("+1", "explicit sign"),
|
||||
("1.0", "float-like"),
|
||||
(" 1", "leading whitespace"),
|
||||
("1 ", "trailing whitespace"),
|
||||
("1\n", "trailing newline"),
|
||||
("abc", "alphabetic"),
|
||||
("1a", "trailing letter"),
|
||||
("a1", "leading letter"),
|
||||
# Unicode digit classes that pass str.isdigit() but are not ASCII.
|
||||
# `²` (U+00B2) is a superscript and would slip past the old guard.
|
||||
("²", "Unicode superscript-2"),
|
||||
# `٢` (U+0662) Arabic-Indic digit two — passes both isdigit() and
|
||||
# isdecimal(), so only an explicit ASCII regex catches it.
|
||||
("٢", "Arabic-Indic digit two"),
|
||||
# `१` (U+0967) Devanagari digit one — same story.
|
||||
("१", "Devanagari digit one"),
|
||||
# Mixed ASCII + Unicode digits.
|
||||
("1٢", "mixed ASCII + Arabic-Indic"),
|
||||
],
|
||||
)
|
||||
def test_rejects_invalid_doc_ids(value, reason):
|
||||
"""Reject empty/zero/leading-zero/non-ASCII/non-digit inputs."""
|
||||
assert is_valid_nextcloud_doc_id(value) is False, f"should reject: {reason}"
|
||||
Reference in New Issue
Block a user