Problem: the hexagonal refactor churns the backend tree for nine more phases; the UI delivery stack (web/ SPA, cmd/desktop Wails wrapper, compose/web image) must move to its own repo first so doc/layout rewrites land once on a backend-only tree. Change: - New repo git.hubris.network/dtoro/oikos-web (v0.33.0): web/, desktop/ (updateURL repointed to oikos-web releases), compose/, own CI (web + desktop jobs), own deploy script (CI-green gate, TOCTOU guard, version-tagged images, prune-to-3), own webhook receiver on :9798 + launchd unit, own compose project publishing the same 8091:80. - Cutover executed on mac-mini in order: oikos stack's web service stopped+removed, oikos-web project brought up on 8091; outer Caddy untouched (targets the published port) — serving + Authentik flow + /wails 404 quirk verified post-cutover. - Stripped from oikos: web/, cmd/desktop/, compose/web/, desktop CI workflow, ci.yml web job, Makefile ui/desktop/desktop-package/install targets, the compose web service, oikos-web from deploy.sh's fallback prune list; wails + go-keyring dropped from go.mod, vendor synced. - README / CONTRIBUTING / AGENTS.md / .agents dev+operations docs now point at the new repo; mbse + mascot design docs carry a path note. Risk: production SPA serving depends on the new pipeline now; rollback is versioned-image re-up of the old web service from a pre-split checkout (port 8091). Desktop builds installed before the split still check dtoro/oikos releases — one manual reinstall, noted in the oikos-web release notes. Verification: go vet, make test (race), make generate-check, golangci (no new findings; baseline down 400→365); post-cutover curls — localhost:8091 200, /wails/runtime.js 404, outer Caddy 302 Authentik.
120 lines
3.3 KiB
JavaScript
120 lines
3.3 KiB
JavaScript
/**
|
|
* @fileoverview Rule to flag unsafe statements in finally block
|
|
* @author Onur Temizkan
|
|
*/
|
|
|
|
"use strict";
|
|
|
|
//------------------------------------------------------------------------------
|
|
// Helpers
|
|
//------------------------------------------------------------------------------
|
|
|
|
const SENTINEL_NODE_TYPE_RETURN_THROW =
|
|
/^(?:Program|(?:Function|Class)(?:Declaration|Expression)|ArrowFunctionExpression)$/u;
|
|
const SENTINEL_NODE_TYPE_BREAK =
|
|
/^(?:Program|(?:Function|Class)(?:Declaration|Expression)|ArrowFunctionExpression|DoWhileStatement|WhileStatement|ForOfStatement|ForInStatement|ForStatement|SwitchStatement)$/u;
|
|
const SENTINEL_NODE_TYPE_CONTINUE =
|
|
/^(?:Program|(?:Function|Class)(?:Declaration|Expression)|ArrowFunctionExpression|DoWhileStatement|WhileStatement|ForOfStatement|ForInStatement|ForStatement)$/u;
|
|
|
|
//------------------------------------------------------------------------------
|
|
// Rule Definition
|
|
//------------------------------------------------------------------------------
|
|
|
|
/** @type {import('../types').Rule.RuleModule} */
|
|
module.exports = {
|
|
meta: {
|
|
type: "problem",
|
|
|
|
docs: {
|
|
description: "Disallow control flow statements in `finally` blocks",
|
|
recommended: true,
|
|
url: "https://eslint.org/docs/latest/rules/no-unsafe-finally",
|
|
},
|
|
|
|
schema: [],
|
|
|
|
messages: {
|
|
unsafeUsage: "Unsafe usage of {{nodeType}}.",
|
|
},
|
|
},
|
|
create(context) {
|
|
/**
|
|
* Checks if the node is the finalizer of a TryStatement
|
|
* @param {ASTNode} node node to check.
|
|
* @returns {boolean} - true if the node is the finalizer of a TryStatement
|
|
*/
|
|
function isFinallyBlock(node) {
|
|
return (
|
|
node.parent.type === "TryStatement" &&
|
|
node.parent.finalizer === node
|
|
);
|
|
}
|
|
|
|
/**
|
|
* Climbs up the tree if the node is not a sentinel node
|
|
* @param {ASTNode} node node to check.
|
|
* @param {string} label label of the break or continue statement
|
|
* @returns {boolean} - return whether the node is a finally block or a sentinel node
|
|
*/
|
|
function isInFinallyBlock(node, label) {
|
|
let labelInside = false;
|
|
let sentinelNodeType;
|
|
|
|
if (node.type === "BreakStatement" && !node.label) {
|
|
sentinelNodeType = SENTINEL_NODE_TYPE_BREAK;
|
|
} else if (node.type === "ContinueStatement") {
|
|
sentinelNodeType = SENTINEL_NODE_TYPE_CONTINUE;
|
|
} else {
|
|
sentinelNodeType = SENTINEL_NODE_TYPE_RETURN_THROW;
|
|
}
|
|
|
|
for (
|
|
let currentNode = node;
|
|
currentNode && !sentinelNodeType.test(currentNode.type);
|
|
currentNode = currentNode.parent
|
|
) {
|
|
if (
|
|
currentNode.parent.label &&
|
|
label &&
|
|
currentNode.parent.label.name === label.name
|
|
) {
|
|
labelInside = true;
|
|
}
|
|
if (isFinallyBlock(currentNode)) {
|
|
if (label && labelInside) {
|
|
return false;
|
|
}
|
|
return true;
|
|
}
|
|
}
|
|
return false;
|
|
}
|
|
|
|
/**
|
|
* Checks whether the possibly-unsafe statement is inside a finally block.
|
|
* @param {ASTNode} node node to check.
|
|
* @returns {void}
|
|
*/
|
|
function check(node) {
|
|
if (isInFinallyBlock(node, node.label)) {
|
|
context.report({
|
|
messageId: "unsafeUsage",
|
|
data: {
|
|
nodeType: node.type,
|
|
},
|
|
node,
|
|
line: node.loc.line,
|
|
column: node.loc.column,
|
|
});
|
|
}
|
|
}
|
|
|
|
return {
|
|
ReturnStatement: check,
|
|
ThrowStatement: check,
|
|
BreakStatement: check,
|
|
ContinueStatement: check,
|
|
};
|
|
},
|
|
};
|