Skip to content

browser-safe-subpaths: walk bench/preferences, deny node:, catch forgotten clients - #434

Merged
TheGreatAxios merged 2 commits into
mainfrom
cl-7124-checkbrowser-safe-subpaths-skips-two-declared-browser
Aug 29, 2026
Merged

TheGreatAxios merged 2 commits into
mainfrom
cl-7124-checkbrowser-safe-subpaths-skips-two-declared-browser

Conversation

@TheGreatAxios

Copy link
Copy Markdown
Contributor

Fixes CL-7124 — https://linear.app/abklabs/issue/CL-7124

Problem

scripts/checks/browser-safe-subpaths.ts walks a hardcoded ENTRIES list. grep -l '"./client"' packages/*/package.json turns up seven packages declaring a browser-safe client, but ENTRIES (browser-safe-subpaths.ts:48-69) only walked five — @corbits/bench/client and @corbits/preferences/client were never audited. DENYLIST_PATTERNS (browser-safe-subpaths.ts:71-76) also had no node:* pattern, so a Node-only import would pass silently.

Change

  • Add { package: "@corbits/bench", subpath: "./client" } and { package: "@corbits/preferences", subpath: "./client" } to ENTRIES.
  • Add /^node:/ to DENYLIST_PATTERNS.
  • Add findUnruledClientExports: fails the check when any packages/*/package.json declares the conventional ./client export with no matching ENTRIES ruling, naming the package and telling the reader exactly what to add.
  • Update the header comment to state the new contract.

Tests

  • scripts/checks/test/browser-safe-subpaths.test.ts: added a red/green case for a node: import being denied, and for an undeclared ./client export failing (and a declared one not failing). Confirmed both were failing before the fix and pass after.
  • bun test scripts/checks/test/browser-safe-subpaths.test.ts — 17 pass.
  • bun run check:browser-safe-subpaths — clean, now walks 11 entries including bench and preferences.
  • bun run check (full gate): the machine was under heavy concurrent load and typecheck reported failures in 6 packages unrelated to this change (@corbits/sidecar-placement, @workbench/hub, @corbits/settings-ui, @corbits/catalog-tools, @workbench/onboarding, @workbench/web); re-running tsc --noEmit for two of them in isolation (sidecar-placement, apps/web) passed clean, confirming these were load-induced kills, not real errors — none of those packages are touched by this change.

Covers the two gaps CL-7124 found: a node:* import should be denied
like any other server-only specifier, and a package.json declaring a
./client export with no ENTRIES ruling should fail loudly instead of
being silently skipped.
…otten clients

grep -l '"./client"' packages/*/package.json turned up seven packages
declaring a browser-safe client, but ENTRIES only walked five —
@corbits/bench/client and @corbits/preferences/client were never
audited. The denylist also had no node:* pattern, so a Node-only
import would pass silently.

Add the two missing entries, deny node:*, and make the check itself
fail when a package.json declares the conventional ./client export
with no matching ENTRIES ruling, so a future client can't be forgotten
the same way.

Fixes CL-7124.
@TheGreatAxios
TheGreatAxios force-pushed the cl-7124-checkbrowser-safe-subpaths-skips-two-declared-browser branch from cc2536e to 74743e5 Compare August 29, 2026 04:46
@TheGreatAxios
TheGreatAxios merged commit 715446a into main Aug 29, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant