mirror of
https://github.com/MadsLorentzen/ai-job-search.git
synced 2026-09-17 08:36:25 +00:00
fix(portals)!: reject unknown flags in all six CLIs
Silently discarded flags produced silently wrong results: jobdanmark with --query (its real flag is --text) returned all 13,862 jobs as if they matched, exit 0, empty stderr - indistinguishable from a real result set. The four bunli CLIs get an argv preflight built from each command's own options object; linkedin and freehire validate parsed flags against per-command known sets. help/version still pass, and add-portal.md's existing bogus-flag-exits-1 contract now holds for the reference implementations contributors copy. One linkedin pin updated: "--jobage-minutes -5" now fails as UNKNOWN_FLAG (the stray -5 token) rather than BAD_ARG - same loud-failure invariant, earlier gate. Review finding F13 (2026-08-19), decision approved by Mads. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
d4e0c64c3c
commit
3bfd525cc4
@@ -68,13 +68,14 @@ describe("LinkedIn CLI flag validation", () => {
|
||||
// parseFlags in cli.ts treats a next-token starting with "-" as absent
|
||||
// (`next.startsWith("-")` → flag becomes boolean `true`), and there is no
|
||||
// `--flag=value` syntax. So "-5" never reaches --jobage-minutes as a value;
|
||||
// parseInt("true") is NaN, and BAD_ARG comes from the NaN branch, not the
|
||||
// `v <= 0` guard. Negatives are unreachable through the CLI as currently parsed.
|
||||
// it parses as a stray flag named "5", which the unknown-flag guard now
|
||||
// rejects before the NaN branch can. Either way the invariant holds: a
|
||||
// negative value fails loudly with exit 1 and a JSON error, never a
|
||||
// silent unfiltered search.
|
||||
const result = await runCLI(["search", "-l", LOCATION, "--jobage-minutes", "-5"]);
|
||||
expect(result.exitCode).not.toBe(0);
|
||||
const err = parsedStderr(result.stderr);
|
||||
expect(err.code).toBe("BAD_ARG");
|
||||
expect(err.error).toMatch(/jobage-minutes/);
|
||||
expect(err.code).toBe("UNKNOWN_FLAG");
|
||||
});
|
||||
});
|
||||
|
||||
@@ -126,3 +127,20 @@ describe("LinkedIn CLI flag validation", () => {
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
|
||||
describe("unknown flag rejection", () => {
|
||||
// add-portal.md's contract: "a bogus flag or missing required arg exits 1
|
||||
// with a JSON error on stderr". A silently discarded flag is worse than an
|
||||
// error: on jobdanmark a wrong flag name returned the entire database
|
||||
// (13,862 results) as if it matched the query (review finding F13,
|
||||
// 2026-08-19). Rejection happens before dispatch, so these are network-free.
|
||||
test("a bogus --flag exits 1 with a JSON error instead of being silently discarded", async () => {
|
||||
const result = await runCLI(["search", "-l", "Denmark", "-q", "test", "--bogus-flag", "xyz"]);
|
||||
expect(result.exitCode).toBe(1);
|
||||
expect(result.stdout).toBe("");
|
||||
const error = JSON.parse(result.stderr);
|
||||
expect(error.code).toBe("UNKNOWN_FLAG");
|
||||
expect(error.error).toContain("--bogus-flag");
|
||||
});
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user