Skip to content

Commit be3056c

Browse files
authored
Let loopback-lint see a positional bind whose port is a call (#875)
2 parents a98e796 + feb1300 commit be3056c

2 files changed

Lines changed: 6 additions & 1 deletion

File tree

‎scripts/loopback-lint-selftest.mjs‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -56,6 +56,9 @@ const EXT_TARGET = 'vscode-ext/vitest.smoketest.config.mts';
5656
*/
5757
const FIXTURES = [
5858
['node, positional', "\nexport function __selftest(s) { s.listen(9999, '127.0.0.1'); }\n"],
59+
// A port computed by a call — `Number(process.env.PORT || 0)` — whose inner
60+
// `)` ends a scan that stops at the first one.
61+
['node, positional', "\nexport function __selftest(s) { s.listen(Number(process.env.PORT || 0), '127.0.0.1'); }\n"],
5962
['node, options object', "\nexport function __selftest(s) { s.listen({ port: 9999, host: '127.0.0.1' }); }\n"],
6063
['@hono/node-server', "\nexport function __selftest(app) { serve({ fetch: app.fetch, port: 9999, hostname: '127.0.0.1' }); }\n"],
6164
['ws, explicit loopback host', "\nexport function __selftest() { return new WebSocketServer({ host: '127.0.0.1' }); }\n"],

‎scripts/loopback-lint.mjs‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,6 +36,8 @@
3636
* options nest again (`headers`, `cookieDomainRewrite`), and `configure`
3737
* takes a function whose body carries braces of its own. A `host` written
3838
* below one of those is a miss, and the audit is what covers it.
39+
* - A positional port may wrap one call (`Number(process.env.PORT || 0)`);
40+
* a port expression nesting parentheses deeper hides the bind.
3941
* - Outside `ws`, it matches only an explicit loopback host. A listener that
4042
* binds every interface (`.listen(port)` with no host) is a different and
4143
* larger problem, and `relay/` does it deliberately from config, so
@@ -127,7 +129,7 @@ const NESTED_KEYS = '(?:[^{}]|\\{(?:[^{}]|\\{[^{}]*\\})*\\})*?';
127129
* exercises is a claim, not a check.
128130
*/
129131
const BIND_FORMS = [
130-
{ label: 'node, positional', re: `\\.listen\\(\\s*[^,)]+,\\s*${LOOPBACK}` },
132+
{ label: 'node, positional', re: `\\.listen\\(\\s*(?:[^,()]|\\([^()]*\\))+,\\s*${LOOPBACK}` },
131133
{ label: 'node, options object', re: `\\.listen\\(\\s*\\{[^}]*?host\\s*:\\s*${LOOPBACK}` },
132134
{ label: '@hono/node-server', re: `\\bserve\\(\\s*\\{[^}]*?hostname\\s*:\\s*${LOOPBACK}` },
133135
{ label: 'ws, explicit loopback host', re: `${WS_NEW}host\\s*:\\s*${LOOPBACK}` },

0 commit comments

Comments
 (0)