3 Commits
Author SHA1 Message Date
zemion 0c47ec5105 Release Schema Tools 0.2.0
Verify / verify (push) Canceled after 0s
2026-09-02 08:04:49 +02:00
zemion 754608e52b Release Schema Tools v0.1.2 2026-09-01 16:20:37 +02:00
zemion 2f60a6d0a7 Release Schema Tools v0.1.1 2026-09-01 14:58:06 +02:00
30 changed files with 2040 additions and 235 deletions
+39
View File
@@ -0,0 +1,39 @@
name: Verify
on:
push:
branches: [main]
pull_request:
workflow_dispatch:
concurrency:
group: verify-${{ gitea.repository }}-${{ gitea.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
verify:
runs-on: ubuntu-latest
timeout-minutes: 45
env:
CI: "true"
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "22"
cache: npm
- name: Select declared npm version
run: npm install --global npm@11.17.0
- name: Install dependencies
run: npm ci
- name: Audit runtime dependencies
run: npm audit --omit=dev --audit-level=moderate
- name: Check, test, and build
run: npm run check
- name: Install browser engines
run: npx playwright install --with-deps chromium firefox webkit
- name: Browser tests
run: npm run test:browser
+25
View File
@@ -1,5 +1,30 @@
# Changelog # Changelog
## 0.2.0 - 2026-09-02
- Added worker-isolated, bounded `pattern` and `patternProperties` validation,
along with broader draft-aware object, array, numeric, dependency and
combiner assertions.
- Added deeper recursive schema comparison and focused XML-language structural
inventories while retaining explicit unsupported-keyword diagnostics.
## 0.1.2 - 2026-09-01
- Refused invalid sample claims when `false` JSON Schemas are reached through local references or required combiners, while selecting the first viable `anyOf` or `oneOf` branch.
- Centralized sample budgets across JSON Schema, OpenAPI, XSD, Relax NG, and Schematron output.
- Applied the 512 KiB aggregate text budget to repeated XML names, attributes, and values, and corrected XML/JSON ceilings to never exceed 2,000 generated values or elements and exactly 20 generated nesting levels.
- Made text truncation UTF-16-safe so it never splits a surrogate pair and corrupts generated XML.
- Preserved direct-root Relax NG `element` patterns in generated samples.
- Added a monotonic 50,000-step work ceiling that refuses over-budget generation, so repeated references, failed alternatives, and non-emitting pattern fan-out cannot amplify work or bypass later mandatory constraints.
- Replaced costly live DOM child-collection conversions with linear sibling-pointer walks and cached bounded XSD type shapes.
- Cached reused schema/reference and XML pattern lookups, and omitted duplicate derived XML attributes so generated samples remain well formed.
- Added adversarial regressions for referenced boolean schemas, exhausted combiners and required values, amplified shared XSD values, wide XML containers, repeated Relax NG references, and exact JSON/XML node limits.
## 0.1.1 - 2026-09-01
- Bounded literal values, aggregate text, derived XML names, collections, and final output during sample generation.
- Added regression coverage for repeated large referenced defaults and always-invalid boolean schemas.
## 0.1.0 - 2026-09-01 ## 0.1.0 - 2026-09-01
- Added bounded local multi-file workspaces and a no-network reference graph for five schema languages. - Added bounded local multi-file workspaces and a no-network reference graph for five schema languages.
+3 -3
View File
@@ -8,13 +8,13 @@ Schema Tools is a standalone local-first application in the [add·ideas Toolbox]
- Safe local workspaces of up to 20 JSON Schema, OpenAPI, XSD, Relax NG XML-syntax, or Schematron documents - Safe local workspaces of up to 20 JSON Schema, OpenAPI, XSD, Relax NG XML-syntax, or Schematron documents
- Reference inventory and graph with local relative resolution, fragments, missing-target diagnostics, and explicit blocking of remote, absolute, and escaping references - Reference inventory and graph with local relative resolution, fragments, missing-target diagnostics, and explicit blocking of remote, absolute, and escaping references
- Focused, CSP-safe JSON Schema instance validation for Draft 6/7, 2019-09, and 2020-12 with bounded local JSON Pointer references - Focused, CSP-safe JSON Schema instance validation for Draft 6/7, 2019-09, and 2020-12 with bounded local JSON Pointer references and worker-isolated `pattern`/`patternProperties`
- Focused OpenAPI 3.0/3.1 structural inspection, operation inventory, component/request-schema sample generation, and obvious breaking-change signals - Focused OpenAPI 3.0/3.1 structural inspection, operation inventory, component/request-schema sample generation, and obvious breaking-change signals
- Well-formedness and structural inspection for XSD, Relax NG XML syntax, and Schematron, plus bounded heuristic XSD/Relax NG samples - Well-formedness and structural inspection for XSD, Relax NG XML syntax, and Schematron, plus bounded heuristic XSD/Relax NG samples
- Conservative comparisons for required properties, types, enums, declarations, operations, parameters, and responses - Conservative comparisons for required properties, types, enums, declarations, operations, parameters, and responses
- Inert rendering, offline PWA support, responsive Toolbox shell integration, and deterministic release archives - Inert rendering, offline PWA support, responsive Toolbox shell integration, and deterministic release archives
Each document is limited to 2 MiB of text, the workspace to 8 MiB and 20 documents, and parsed trees, references, instances, samples, validation work, and diagnostic output have independent bounds. DTD/entity declarations, remote references, Schematron XPath, extension code, JSON Schema `pattern`, and `patternProperties` are never executed. JSON Schema validation covers a documented assertion subset rather than claiming full specification conformance. XML languages receive structural inspection—not instance validation—and OpenAPI checks are intentionally focused. Each document is limited to 2 MiB of text, the workspace to 8 MiB and 20 documents, and parsed trees, references, instances, samples, validation work, and diagnostic output have independent bounds. One shared generator budget limits samples to 50,000 monotonic work steps, 2,000 generated JSON values or XML elements, exactly 20 generated nesting levels, 512 KiB of aggregate derived text, 1,024 UTF-16 code units per literal without splitting surrogate pairs, and 2 MiB of serialized output. Generation is refused if another work step would exceed that ceiling; structural and text ceilings instead return a visibly bounded heuristic sample where one can still be formed. DTD/entity declarations, remote references, Schematron XPath, and extension code are never executed. JSON Schema regular expressions are evaluated only in a disposable worker, with limits of 256 expressions, 4,096 characters per expression, 5,000 candidate strings, 250,000 pair evaluations, and a one-second deadline. JSON Schema validation covers a documented assertion subset rather than claiming full specification conformance. XML languages receive structural inspection—not instance validation—and OpenAPI checks are intentionally focused.
See [Architecture](docs/ARCHITECTURE.md) and [Privacy and security](docs/PRIVACY-SECURITY.md) for the exact capability boundaries. See [Architecture](docs/ARCHITECTURE.md) and [Privacy and security](docs/PRIVACY-SECURITY.md) for the exact capability boundaries.
@@ -30,7 +30,7 @@ npm run test:browser
## Release ## Release
`npm run release:artifact` creates deterministic `release/schema-tools-0.1.0.zip` and checksum files. `npm run release:artifact` creates deterministic `release/schema-tools-0.2.0.zip` and checksum files.
## Licence ## Licence
+2 -2
View File
@@ -1,7 +1,7 @@
# Corresponding source # Corresponding source
The corresponding source for Schema Tools 0.1.0 is available at: The corresponding source for Schema Tools 0.2.0 is available at:
https://git.add-ideas.de/lotobo/schema-tools/src/tag/v0.1.0 https://git.add-ideas.de/lotobo/schema-tools/src/tag/v0.2.0
Build with Node.js 22, npm 11, `npm ci`, and `npm run release:artifact`. Build with Node.js 22, npm 11, `npm ci`, and `npm run release:artifact`.
+4 -4
View File
@@ -1,12 +1,12 @@
# Third-party notices # Third-party notices
Schema Tools 0.1.0 directly depends on these runtime packages: Schema Tools 0.2.0 directly depends on these runtime packages:
| Package | Pinned version | Declared licence | | Package | Pinned version | Declared licence |
| -------------------------------- | -------------: | ---------------- | | -------------------------------- | -------------: | ---------------- |
| `@add-ideas/toolbox-contract` | 0.2.3 | Apache-2.0 | | `@add-ideas/toolbox-contract` | 0.3.0 | Apache-2.0 |
| `@add-ideas/toolbox-helpers` | 0.1.0 | GPL-3.0-or-later | | `@add-ideas/toolbox-helpers` | 0.2.0 | GPL-3.0-or-later |
| `@add-ideas/toolbox-shell-react` | 0.2.3 | Apache-2.0 | | `@add-ideas/toolbox-shell-react` | 0.3.0 | Apache-2.0 |
| `react` | 19.2.8 | MIT | | `react` | 19.2.8 | MIT |
| `react-dom` | 19.2.8 | MIT | | `react-dom` | 19.2.8 | MIT |
| `yaml` | 2.9.0 | ISC | | `yaml` | 2.9.0 | ISC |
+6 -4
View File
@@ -2,10 +2,12 @@
Schema Tools is a static React/Vite application inside the shared Toolbox shell. `src/schema/model.ts` is the bounded trust boundary: it normalizes workspace names, parses JSON/YAML/XML, inventories language structures and references, performs eligible JSON instance validation, generates samples, and produces conservative comparison signals. React renders only text and native controls; no schema content is inserted as HTML. Schema Tools is a static React/Vite application inside the shared Toolbox shell. `src/schema/model.ts` is the bounded trust boundary: it normalizes workspace names, parses JSON/YAML/XML, inventories language structures and references, performs eligible JSON instance validation, generates samples, and produces conservative comparison signals. React renders only text and native controls; no schema content is inserted as HTML.
JSON and YAML values are converted into an acyclic, prototype-safe JSON model with limits on source length, node count, depth, and collection width. JSON Schema instance validation is a CSP-safe interpreter selected for Draft 6, Draft 7, 2019-09, or 2020-12 behavior; it never generates or evaluates code. The focused subset covers boolean schemas, local `$ref` with JSON Pointer fragments, `type`, `enum`, `const`, numeric bounds and `multipleOf`, string lengths, object properties/required/additional properties/property names/dependencies, array items/tuples/contains/uniqueness and size, combiners, negation, and draft-appropriate conditionals. Validation has a 250,000-step and 1,000-diagnostic ceiling. JSON and YAML values are converted into an acyclic, prototype-safe JSON model with limits on source length, node count, depth, and collection width. JSON Schema instance validation is a CSP-safe interpreter selected for Draft 6, Draft 7, 2019-09, or 2020-12 behavior; it never generates or evaluates code. The focused subset covers boolean schemas, local `$ref` with JSON Pointer fragments, `type`, `enum`, `const`, numeric bounds and `multipleOf`, string lengths and patterns, object properties/required/additional properties/property names/pattern properties/dependencies, array items/tuples/contains/uniqueness and size, combiners, negation, and draft-appropriate conditionals. Validation has a 250,000-step and 1,000-diagnostic ceiling.
Every reference is classified before validation. Only fragments and relative filenames supplied in the current workspace are eligible. Root `$id`/legacy `id` values are deliberately ignored so relative references remain anchored to workspace filenames; nested identifier scopes, named anchors, dynamic/recursive references, and unevaluated keywords are outside the subset and cause a visible refusal. All participating JSON Schema files must use one declared draft. Formats and unknown extension keywords are annotations. Schemas containing `pattern` or `patternProperties` are refused because JavaScript regular-expression execution cannot be reliably time-bounded; they remain inspectable. Decimal arithmetic uses JavaScript numbers, so `multipleOf` applies a small floating-point tolerance. Every reference is classified before validation. Only fragments and relative filenames supplied in the current workspace are eligible. Root `$id`/legacy `id` values are deliberately ignored so relative references remain anchored to workspace filenames; nested identifier scopes, named anchors, dynamic/recursive references, and unevaluated keywords are outside the subset and cause a visible refusal. All participating JSON Schema files must use one declared draft. Formats and unknown extension keywords are annotations. `pattern` and `patternProperties` expressions and candidate strings are deduplicated and sent as one bounded batch to a fresh module worker; the caller terminates that worker after one second, including while one pathological `RegExp.test` is stalled. No partial result is accepted. Decimal arithmetic uses JavaScript numbers, so `multipleOf` applies a small floating-point tolerance.
OpenAPI JSON/YAML receives focused document, operation, response, reference, sample, and comparison logic. It does not run requests and does not claim full OpenAPI conformance. XML uses the browser's inert `DOMParser` only after rejecting DTD and entity declarations. XSD, Relax NG XML syntax, and Schematron are checked for well-formedness and structurally inventoried. Schematron XPath and extensions are retained as text and never executed. XSD and Relax NG sample generation deliberately follows a bounded first branch and is labelled heuristic. OpenAPI JSON/YAML receives focused document, operation, response, reference, sample, and comparison logic. It does not run requests and does not claim full OpenAPI conformance. XML uses the browser's inert `DOMParser` only after rejecting DTD and entity declarations. Element counting and depth inspection use a linear sibling-pointer walk, avoiding repeated conversion of live DOM child collections. XSD, Relax NG XML syntax, and Schematron are checked for well-formedness and structurally inventoried. Schematron XPath and extensions are retained as text and never executed. XSD and Relax NG sample generation deliberately follows a bounded first branch and is labelled heuristic. XSD named-type shapes are inspected once and cached within one generation; Relax NG grammars and direct-root `element` patterns use the same renderer, and pattern-only wrappers do not consume generated nesting depth.
The PWA uses only relative URLs, so the same build works standalone or below a nested portal route. Its service worker caches same-origin files from its own scope. No worker, storage database, server API, telemetry path, or remote schema resolver exists in v0.1.0. All sample paths share one budget implementation. It admits at most 50,000 monotonic generator work steps and 2,000 generated JSON values or XML elements across exactly 20 generated levels (the root is level one), accounts for at most 512 KiB of aggregate derived keys, names, attribute values, and content, caps each copied literal at 1,024 UTF-16 code units without splitting a surrogate pair, and rejects serialized output above 2 MiB. References and schema/pattern combiners do not consume generated depth, but every build, copy, reference, alternative, XML type inspection, and XML pattern visit consumes work before expansion. Per-generation caches ensure repeated JSON references, wide property collections, XML child collections, inline types, text, and name normalization are not rescanned without bound. The work counter is deliberately not restored when a failed heuristic alternative rolls back its node/text checkpoint, and generation is refused rather than returning an ambiguously partial result when a 50,001st work step is attempted. Node, depth, and text ceilings can instead omit bounded material with a visible notice. Repeated references consume node and text counters for every emitted occurrence. Duplicate or fallback-colliding derived XML attribute names are omitted with a notice to preserve well-formed output. A `false` JSON Schema reached through a selected local reference or mandatory `allOf` branch aborts generation; `anyOf` and `oneOf` skip definitely impossible boolean branches and use the first viable heuristic branch only while the complete attempt remains within budget.
The PWA uses only relative URLs, so the same build works standalone or below a nested portal route. Its service worker caches same-origin files from its own scope. The regex worker receives only the already-local expressions and candidate strings for one validation request and is then terminated. No storage database, server API, telemetry path, or remote schema resolver is used.
+3 -3
View File
@@ -2,8 +2,8 @@
Schema sources, instances, diagnostics, comparisons, and generated samples stay in page memory. There are no accounts, analytics, telemetry, persistence, remote imports, or runtime third-party assets. Explicit source links are normal navigation only. Clearing or closing the page releases application references but cannot promise forensic erasure from browser or operating-system memory. Schema sources, instances, diagnostics, comparisons, and generated samples stay in page memory. There are no accounts, analytics, telemetry, persistence, remote imports, or runtime third-party assets. Explicit source links are normal navigation only. Clearing or closing the page releases application references but cannot promise forensic erasure from browser or operating-system memory.
Each source is limited to 2 MiB of text; a workspace is limited to 20 documents and 8 MiB. JSON/YAML trees are capped at 25,000 values, 48 levels, and 2,000 entries in one collection. XML is capped at 25,000 elements and 48 levels. References, samples, instances, and diagnostics have separate caps. File byte gates are deliberately conservative before `File.text()` decoding. Each source is limited to 2 MiB of text; a workspace is limited to 20 documents and 8 MiB. JSON/YAML trees are capped at 25,000 values, 48 levels, and 2,000 entries in one collection. XML is capped at 25,000 elements and 48 levels. References, instances, and diagnostics have separate caps. A shared sample budget is limited to 50,000 monotonic work steps, exactly 2,000 generated JSON values or XML elements, exactly 20 generated nesting levels, 512 KiB of aggregate derived text, 1,024 UTF-16 code units per copied literal without splitting surrogate pairs, and 2 MiB of serialized output. Reusing a local definition consumes the same aggregate counters on every attempt and generated occurrence; failed heuristic alternatives never refund work. Reaching the work ceiling refuses the generation operation, so exhaustion cannot be mistaken for a viable choice or skip a later mandatory constraint. File byte gates are deliberately conservative before `File.text()` decoding.
Prototype-sensitive JSON keys, cyclic YAML aliases, NUL input, DTD/entity declarations, absolute/remote/escaping references, and executable schema extensions are rejected. Schematron expressions and imported XML are never executed. JSON Schema formats are annotations, and regex-bearing schema keywords are not executed. The focused validator interprets eligible schemas without dynamic code generation, remote loading, custom code, or `unsafe-eval`; work and diagnostic counts are capped. Prototype-sensitive JSON keys, cyclic YAML aliases, NUL input, DTD/entity declarations, absolute/remote/escaping references, and executable schema extensions are rejected. Schematron expressions and imported XML are never executed. JSON Schema formats are annotations. Regex-bearing keywords are evaluated in a fresh worker that is terminated on completion or after one second; expression count and length, candidate count, and total pair evaluations are capped before dispatch. The focused validator interprets eligible schemas without dynamic code generation, remote loading, custom code, or `unsafe-eval`; work and diagnostic counts are capped.
Sample generation and compatibility results are review aids. A generated document is not guaranteed to satisfy every constraint, and an absence of reported changes does not prove compatibility. JSON validation requires a single declared draft and uses local workspace filenames rather than identifier URIs. Named anchors, nested identifier scopes, dynamic/recursive references, unevaluated keywords, regular expressions, and full meta-schema validation are outside v0.1.0. XSD, Relax NG, and Schematron instance validation is also outside v0.1.0; OpenAPI inspection is not a full conformance certification. Sample generation and compatibility results are review aids. A generated document is not guaranteed to satisfy every constraint, and an absence of reported changes does not prove compatibility. Generation refuses a definitely impossible selected `false` JSON Schema branch but does not prove broader satisfiability. JSON validation requires a single declared draft and uses local workspace filenames rather than identifier URIs. Named anchors, nested identifier scopes, dynamic/recursive references, unevaluated keywords, and full meta-schema validation remain outside the focused subset. XSD, Relax NG, and Schematron instance validation is also outside the current scope; OpenAPI inspection is not a full conformance certification.
+22 -23
View File
@@ -1,23 +1,23 @@
{ {
"name": "schema-tools", "name": "schema-tools",
"version": "0.1.0", "version": "0.2.0",
"lockfileVersion": 3, "lockfileVersion": 3,
"requires": true, "requires": true,
"packages": { "packages": {
"": { "": {
"name": "schema-tools", "name": "schema-tools",
"version": "0.1.0", "version": "0.2.0",
"license": "GPL-3.0-or-later", "license": "GPL-3.0-or-later",
"dependencies": { "dependencies": {
"@add-ideas/toolbox-contract": "0.2.3", "@add-ideas/toolbox-contract": "0.3.0",
"@add-ideas/toolbox-helpers": "0.1.0", "@add-ideas/toolbox-helpers": "0.2.0",
"@add-ideas/toolbox-shell-react": "0.2.3", "@add-ideas/toolbox-shell-react": "0.3.0",
"react": "19.2.8", "react": "19.2.8",
"react-dom": "19.2.8", "react-dom": "19.2.8",
"yaml": "2.9.0" "yaml": "2.9.0"
}, },
"devDependencies": { "devDependencies": {
"@add-ideas/toolbox-testkit": "0.2.3", "@add-ideas/toolbox-testkit": "0.3.0",
"@eslint/js": "10.0.1", "@eslint/js": "10.0.1",
"@playwright/test": "1.62.1", "@playwright/test": "1.62.1",
"@testing-library/jest-dom": "6.9.1", "@testing-library/jest-dom": "6.9.1",
@@ -43,24 +43,24 @@
} }
}, },
"node_modules/@add-ideas/toolbox-contract": { "node_modules/@add-ideas/toolbox-contract": {
"version": "0.2.3", "version": "0.3.0",
"license": "Apache-2.0", "resolved": "https://git.add-ideas.de/api/packages/lotobo/npm/%40add-ideas%2Ftoolbox-contract/-/0.3.0/toolbox-contract-0.3.0.tgz",
"engines": { "integrity": "sha512-dKrK7BjOFwqJaBfJuhKxZKIld4sH0AKjEn6a0yLnbdMUFY+fFv4VSLGV2tNSBD016gumc2iNqOjUj/ld7x4rtA==",
"node": ">=20" "license": "Apache-2.0"
}
}, },
"node_modules/@add-ideas/toolbox-helpers": { "node_modules/@add-ideas/toolbox-helpers": {
"version": "0.1.0", "version": "0.2.0",
"license": "GPL-3.0-or-later", "resolved": "https://git.add-ideas.de/api/packages/lotobo/npm/%40add-ideas%2Ftoolbox-helpers/-/0.2.0/toolbox-helpers-0.2.0.tgz",
"engines": { "integrity": "sha512-SdOqkw+P+3J3fa5iVkzb5P15rVepB001GNV21Oh8w0CZcVL+YRltgD/s+MVcTyrNijWQf3E5vtQON/3N2LLyKg==",
"node": ">=22" "license": "GPL-3.0-or-later"
}
}, },
"node_modules/@add-ideas/toolbox-shell-react": { "node_modules/@add-ideas/toolbox-shell-react": {
"version": "0.2.3", "version": "0.3.0",
"resolved": "https://git.add-ideas.de/api/packages/lotobo/npm/%40add-ideas%2Ftoolbox-shell-react/-/0.3.0/toolbox-shell-react-0.3.0.tgz",
"integrity": "sha512-74p6JzAOG0YCAKdlc1hLofV4ZIko7vb448S75cIiM88PKm93EHl5VD7g8YVyfM56Ui97UY9dmy+Whiq4sGzpsg==",
"license": "Apache-2.0", "license": "Apache-2.0",
"dependencies": { "dependencies": {
"@add-ideas/toolbox-contract": "0.2.3" "@add-ideas/toolbox-contract": "0.3.0"
}, },
"peerDependencies": { "peerDependencies": {
"react": ">=18 <20", "react": ">=18 <20",
@@ -68,17 +68,16 @@
} }
}, },
"node_modules/@add-ideas/toolbox-testkit": { "node_modules/@add-ideas/toolbox-testkit": {
"version": "0.2.3", "version": "0.3.0",
"resolved": "https://git.add-ideas.de/api/packages/lotobo/npm/%40add-ideas%2Ftoolbox-testkit/-/0.3.0/toolbox-testkit-0.3.0.tgz",
"integrity": "sha512-4Fk+oSvZFspOMIXr8Xy040nhAaBsIQAzsGyXWSpjn3+k3yBKq7nB1r5zCHhsXzfdLzvPDAx2KcmSNOhM330D9w==",
"dev": true, "dev": true,
"license": "Apache-2.0", "license": "Apache-2.0",
"dependencies": { "dependencies": {
"@add-ideas/toolbox-contract": "0.2.3" "@add-ideas/toolbox-contract": "0.3.0"
}, },
"bin": { "bin": {
"toolbox-check": "dist/cli.js" "toolbox-check": "dist/cli.js"
},
"engines": {
"node": ">=20"
} }
}, },
"node_modules/@adobe/css-tools": { "node_modules/@adobe/css-tools": {
+5 -5
View File
@@ -1,6 +1,6 @@
{ {
"name": "schema-tools", "name": "schema-tools",
"version": "0.1.0", "version": "0.2.0",
"description": "Inspect, validate, compare, and derive examples from schemas locally in the browser.", "description": "Inspect, validate, compare, and derive examples from schemas locally in the browser.",
"license": "GPL-3.0-or-later", "license": "GPL-3.0-or-later",
"author": "Albrecht Degering", "author": "Albrecht Degering",
@@ -39,15 +39,15 @@
"release:artifact": "npm run check && npm run test:browser && npm run package:release -- --force" "release:artifact": "npm run check && npm run test:browser && npm run package:release -- --force"
}, },
"dependencies": { "dependencies": {
"@add-ideas/toolbox-contract": "0.2.3", "@add-ideas/toolbox-contract": "0.3.0",
"@add-ideas/toolbox-helpers": "0.1.0", "@add-ideas/toolbox-helpers": "0.2.0",
"@add-ideas/toolbox-shell-react": "0.2.3", "@add-ideas/toolbox-shell-react": "0.3.0",
"react": "19.2.8", "react": "19.2.8",
"react-dom": "19.2.8", "react-dom": "19.2.8",
"yaml": "2.9.0" "yaml": "2.9.0"
}, },
"devDependencies": { "devDependencies": {
"@add-ideas/toolbox-testkit": "0.2.3", "@add-ideas/toolbox-testkit": "0.3.0",
"@eslint/js": "10.0.1", "@eslint/js": "10.0.1",
"@playwright/test": "1.62.1", "@playwright/test": "1.62.1",
"@testing-library/jest-dom": "6.9.1", "@testing-library/jest-dom": "6.9.1",
+20 -2
View File
@@ -15,7 +15,25 @@ export default defineConfig({
timeout: 180_000, timeout: 180_000,
}, },
projects: [ projects: [
{ name: "chromium", use: { ...devices["Desktop Chrome"] } }, {
{ name: "firefox", use: { ...devices["Desktop Firefox"] } }, name: "chromium",
testIgnore: /responsive\.spec\.ts/,
use: { ...devices["Desktop Chrome"] },
},
{
name: "firefox",
testIgnore: /responsive\.spec\.ts/,
use: { ...devices["Desktop Firefox"] },
},
{
name: "webkit",
testIgnore: /responsive\.spec\.ts/,
use: { ...devices["Desktop Safari"] },
},
{
name: "mobile-chromium",
testMatch: /responsive\.spec\.ts/,
use: { ...devices["Pixel 5"] },
},
], ],
}); });
+25
View File
@@ -1,5 +1,30 @@
# Changelog # Changelog
## 0.2.0 - 2026-09-02
- Added worker-isolated, bounded `pattern` and `patternProperties` validation,
along with broader draft-aware object, array, numeric, dependency and
combiner assertions.
- Added deeper recursive schema comparison and focused XML-language structural
inventories while retaining explicit unsupported-keyword diagnostics.
## 0.1.2 - 2026-09-01
- Refused invalid sample claims when `false` JSON Schemas are reached through local references or required combiners, while selecting the first viable `anyOf` or `oneOf` branch.
- Centralized sample budgets across JSON Schema, OpenAPI, XSD, Relax NG, and Schematron output.
- Applied the 512 KiB aggregate text budget to repeated XML names, attributes, and values, and corrected XML/JSON ceilings to never exceed 2,000 generated values or elements and exactly 20 generated nesting levels.
- Made text truncation UTF-16-safe so it never splits a surrogate pair and corrupts generated XML.
- Preserved direct-root Relax NG `element` patterns in generated samples.
- Added a monotonic 50,000-step work ceiling that refuses over-budget generation, so repeated references, failed alternatives, and non-emitting pattern fan-out cannot amplify work or bypass later mandatory constraints.
- Replaced costly live DOM child-collection conversions with linear sibling-pointer walks and cached bounded XSD type shapes.
- Cached reused schema/reference and XML pattern lookups, and omitted duplicate derived XML attributes so generated samples remain well formed.
- Added adversarial regressions for referenced boolean schemas, exhausted combiners and required values, amplified shared XSD values, wide XML containers, repeated Relax NG references, and exact JSON/XML node limits.
## 0.1.1 - 2026-09-01
- Bounded literal values, aggregate text, derived XML names, collections, and final output during sample generation.
- Added regression coverage for repeated large referenced defaults and always-invalid boolean schemas.
## 0.1.0 - 2026-09-01 ## 0.1.0 - 2026-09-01
- Added bounded local multi-file workspaces and a no-network reference graph for five schema languages. - Added bounded local multi-file workspaces and a no-network reference graph for five schema languages.
+3 -3
View File
@@ -1,5 +1,5 @@
============================================================================== ==============================================================================
@add-ideas/toolbox-contract@0.2.3 @add-ideas/toolbox-contract@0.3.0
Declared licence: Apache-2.0 Declared licence: Apache-2.0
============================================================================== ==============================================================================
--- LICENSE --- --- LICENSE ---
@@ -198,7 +198,7 @@ Declared licence: Apache-2.0
============================================================================== ==============================================================================
@add-ideas/toolbox-helpers@0.1.0 @add-ideas/toolbox-helpers@0.2.0
Declared licence: GPL-3.0-or-later Declared licence: GPL-3.0-or-later
============================================================================== ==============================================================================
--- LICENSE --- --- LICENSE ---
@@ -879,7 +879,7 @@ Public License instead of this License. But first, please read
============================================================================== ==============================================================================
@add-ideas/toolbox-shell-react@0.2.3 @add-ideas/toolbox-shell-react@0.3.0
Declared licence: Apache-2.0 Declared licence: Apache-2.0
============================================================================== ==============================================================================
--- LICENSE --- --- LICENSE ---
+3 -3
View File
@@ -8,13 +8,13 @@ Schema Tools is a standalone local-first application in the [add·ideas Toolbox]
- Safe local workspaces of up to 20 JSON Schema, OpenAPI, XSD, Relax NG XML-syntax, or Schematron documents - Safe local workspaces of up to 20 JSON Schema, OpenAPI, XSD, Relax NG XML-syntax, or Schematron documents
- Reference inventory and graph with local relative resolution, fragments, missing-target diagnostics, and explicit blocking of remote, absolute, and escaping references - Reference inventory and graph with local relative resolution, fragments, missing-target diagnostics, and explicit blocking of remote, absolute, and escaping references
- Focused, CSP-safe JSON Schema instance validation for Draft 6/7, 2019-09, and 2020-12 with bounded local JSON Pointer references - Focused, CSP-safe JSON Schema instance validation for Draft 6/7, 2019-09, and 2020-12 with bounded local JSON Pointer references and worker-isolated `pattern`/`patternProperties`
- Focused OpenAPI 3.0/3.1 structural inspection, operation inventory, component/request-schema sample generation, and obvious breaking-change signals - Focused OpenAPI 3.0/3.1 structural inspection, operation inventory, component/request-schema sample generation, and obvious breaking-change signals
- Well-formedness and structural inspection for XSD, Relax NG XML syntax, and Schematron, plus bounded heuristic XSD/Relax NG samples - Well-formedness and structural inspection for XSD, Relax NG XML syntax, and Schematron, plus bounded heuristic XSD/Relax NG samples
- Conservative comparisons for required properties, types, enums, declarations, operations, parameters, and responses - Conservative comparisons for required properties, types, enums, declarations, operations, parameters, and responses
- Inert rendering, offline PWA support, responsive Toolbox shell integration, and deterministic release archives - Inert rendering, offline PWA support, responsive Toolbox shell integration, and deterministic release archives
Each document is limited to 2 MiB of text, the workspace to 8 MiB and 20 documents, and parsed trees, references, instances, samples, validation work, and diagnostic output have independent bounds. DTD/entity declarations, remote references, Schematron XPath, extension code, JSON Schema `pattern`, and `patternProperties` are never executed. JSON Schema validation covers a documented assertion subset rather than claiming full specification conformance. XML languages receive structural inspection—not instance validation—and OpenAPI checks are intentionally focused. Each document is limited to 2 MiB of text, the workspace to 8 MiB and 20 documents, and parsed trees, references, instances, samples, validation work, and diagnostic output have independent bounds. One shared generator budget limits samples to 50,000 monotonic work steps, 2,000 generated JSON values or XML elements, exactly 20 generated nesting levels, 512 KiB of aggregate derived text, 1,024 UTF-16 code units per literal without splitting surrogate pairs, and 2 MiB of serialized output. Generation is refused if another work step would exceed that ceiling; structural and text ceilings instead return a visibly bounded heuristic sample where one can still be formed. DTD/entity declarations, remote references, Schematron XPath, and extension code are never executed. JSON Schema regular expressions are evaluated only in a disposable worker, with limits of 256 expressions, 4,096 characters per expression, 5,000 candidate strings, 250,000 pair evaluations, and a one-second deadline. JSON Schema validation covers a documented assertion subset rather than claiming full specification conformance. XML languages receive structural inspection—not instance validation—and OpenAPI checks are intentionally focused.
See [Architecture](docs/ARCHITECTURE.md) and [Privacy and security](docs/PRIVACY-SECURITY.md) for the exact capability boundaries. See [Architecture](docs/ARCHITECTURE.md) and [Privacy and security](docs/PRIVACY-SECURITY.md) for the exact capability boundaries.
@@ -30,7 +30,7 @@ npm run test:browser
## Release ## Release
`npm run release:artifact` creates deterministic `release/schema-tools-0.1.0.zip` and checksum files. `npm run release:artifact` creates deterministic `release/schema-tools-0.2.0.zip` and checksum files.
## Licence ## Licence
+2 -2
View File
@@ -1,7 +1,7 @@
# Corresponding source # Corresponding source
The corresponding source for Schema Tools 0.1.0 is available at: The corresponding source for Schema Tools 0.2.0 is available at:
https://git.add-ideas.de/lotobo/schema-tools/src/tag/v0.1.0 https://git.add-ideas.de/lotobo/schema-tools/src/tag/v0.2.0
Build with Node.js 22, npm 11, `npm ci`, and `npm run release:artifact`. Build with Node.js 22, npm 11, `npm ci`, and `npm run release:artifact`.
+4 -4
View File
@@ -1,12 +1,12 @@
# Third-party notices # Third-party notices
Schema Tools 0.1.0 directly depends on these runtime packages: Schema Tools 0.2.0 directly depends on these runtime packages:
| Package | Pinned version | Declared licence | | Package | Pinned version | Declared licence |
| -------------------------------- | -------------: | ---------------- | | -------------------------------- | -------------: | ---------------- |
| `@add-ideas/toolbox-contract` | 0.2.3 | Apache-2.0 | | `@add-ideas/toolbox-contract` | 0.3.0 | Apache-2.0 |
| `@add-ideas/toolbox-helpers` | 0.1.0 | GPL-3.0-or-later | | `@add-ideas/toolbox-helpers` | 0.2.0 | GPL-3.0-or-later |
| `@add-ideas/toolbox-shell-react` | 0.2.3 | Apache-2.0 | | `@add-ideas/toolbox-shell-react` | 0.3.0 | Apache-2.0 |
| `react` | 19.2.8 | MIT | | `react` | 19.2.8 | MIT |
| `react-dom` | 19.2.8 | MIT | | `react-dom` | 19.2.8 | MIT |
| `yaml` | 2.9.0 | ISC | | `yaml` | 2.9.0 | ISC |
+6 -4
View File
@@ -2,10 +2,12 @@
Schema Tools is a static React/Vite application inside the shared Toolbox shell. `src/schema/model.ts` is the bounded trust boundary: it normalizes workspace names, parses JSON/YAML/XML, inventories language structures and references, performs eligible JSON instance validation, generates samples, and produces conservative comparison signals. React renders only text and native controls; no schema content is inserted as HTML. Schema Tools is a static React/Vite application inside the shared Toolbox shell. `src/schema/model.ts` is the bounded trust boundary: it normalizes workspace names, parses JSON/YAML/XML, inventories language structures and references, performs eligible JSON instance validation, generates samples, and produces conservative comparison signals. React renders only text and native controls; no schema content is inserted as HTML.
JSON and YAML values are converted into an acyclic, prototype-safe JSON model with limits on source length, node count, depth, and collection width. JSON Schema instance validation is a CSP-safe interpreter selected for Draft 6, Draft 7, 2019-09, or 2020-12 behavior; it never generates or evaluates code. The focused subset covers boolean schemas, local `$ref` with JSON Pointer fragments, `type`, `enum`, `const`, numeric bounds and `multipleOf`, string lengths, object properties/required/additional properties/property names/dependencies, array items/tuples/contains/uniqueness and size, combiners, negation, and draft-appropriate conditionals. Validation has a 250,000-step and 1,000-diagnostic ceiling. JSON and YAML values are converted into an acyclic, prototype-safe JSON model with limits on source length, node count, depth, and collection width. JSON Schema instance validation is a CSP-safe interpreter selected for Draft 6, Draft 7, 2019-09, or 2020-12 behavior; it never generates or evaluates code. The focused subset covers boolean schemas, local `$ref` with JSON Pointer fragments, `type`, `enum`, `const`, numeric bounds and `multipleOf`, string lengths and patterns, object properties/required/additional properties/property names/pattern properties/dependencies, array items/tuples/contains/uniqueness and size, combiners, negation, and draft-appropriate conditionals. Validation has a 250,000-step and 1,000-diagnostic ceiling.
Every reference is classified before validation. Only fragments and relative filenames supplied in the current workspace are eligible. Root `$id`/legacy `id` values are deliberately ignored so relative references remain anchored to workspace filenames; nested identifier scopes, named anchors, dynamic/recursive references, and unevaluated keywords are outside the subset and cause a visible refusal. All participating JSON Schema files must use one declared draft. Formats and unknown extension keywords are annotations. Schemas containing `pattern` or `patternProperties` are refused because JavaScript regular-expression execution cannot be reliably time-bounded; they remain inspectable. Decimal arithmetic uses JavaScript numbers, so `multipleOf` applies a small floating-point tolerance. Every reference is classified before validation. Only fragments and relative filenames supplied in the current workspace are eligible. Root `$id`/legacy `id` values are deliberately ignored so relative references remain anchored to workspace filenames; nested identifier scopes, named anchors, dynamic/recursive references, and unevaluated keywords are outside the subset and cause a visible refusal. All participating JSON Schema files must use one declared draft. Formats and unknown extension keywords are annotations. `pattern` and `patternProperties` expressions and candidate strings are deduplicated and sent as one bounded batch to a fresh module worker; the caller terminates that worker after one second, including while one pathological `RegExp.test` is stalled. No partial result is accepted. Decimal arithmetic uses JavaScript numbers, so `multipleOf` applies a small floating-point tolerance.
OpenAPI JSON/YAML receives focused document, operation, response, reference, sample, and comparison logic. It does not run requests and does not claim full OpenAPI conformance. XML uses the browser's inert `DOMParser` only after rejecting DTD and entity declarations. XSD, Relax NG XML syntax, and Schematron are checked for well-formedness and structurally inventoried. Schematron XPath and extensions are retained as text and never executed. XSD and Relax NG sample generation deliberately follows a bounded first branch and is labelled heuristic. OpenAPI JSON/YAML receives focused document, operation, response, reference, sample, and comparison logic. It does not run requests and does not claim full OpenAPI conformance. XML uses the browser's inert `DOMParser` only after rejecting DTD and entity declarations. Element counting and depth inspection use a linear sibling-pointer walk, avoiding repeated conversion of live DOM child collections. XSD, Relax NG XML syntax, and Schematron are checked for well-formedness and structurally inventoried. Schematron XPath and extensions are retained as text and never executed. XSD and Relax NG sample generation deliberately follows a bounded first branch and is labelled heuristic. XSD named-type shapes are inspected once and cached within one generation; Relax NG grammars and direct-root `element` patterns use the same renderer, and pattern-only wrappers do not consume generated nesting depth.
The PWA uses only relative URLs, so the same build works standalone or below a nested portal route. Its service worker caches same-origin files from its own scope. No worker, storage database, server API, telemetry path, or remote schema resolver exists in v0.1.0. All sample paths share one budget implementation. It admits at most 50,000 monotonic generator work steps and 2,000 generated JSON values or XML elements across exactly 20 generated levels (the root is level one), accounts for at most 512 KiB of aggregate derived keys, names, attribute values, and content, caps each copied literal at 1,024 UTF-16 code units without splitting a surrogate pair, and rejects serialized output above 2 MiB. References and schema/pattern combiners do not consume generated depth, but every build, copy, reference, alternative, XML type inspection, and XML pattern visit consumes work before expansion. Per-generation caches ensure repeated JSON references, wide property collections, XML child collections, inline types, text, and name normalization are not rescanned without bound. The work counter is deliberately not restored when a failed heuristic alternative rolls back its node/text checkpoint, and generation is refused rather than returning an ambiguously partial result when a 50,001st work step is attempted. Node, depth, and text ceilings can instead omit bounded material with a visible notice. Repeated references consume node and text counters for every emitted occurrence. Duplicate or fallback-colliding derived XML attribute names are omitted with a notice to preserve well-formed output. A `false` JSON Schema reached through a selected local reference or mandatory `allOf` branch aborts generation; `anyOf` and `oneOf` skip definitely impossible boolean branches and use the first viable heuristic branch only while the complete attempt remains within budget.
The PWA uses only relative URLs, so the same build works standalone or below a nested portal route. Its service worker caches same-origin files from its own scope. The regex worker receives only the already-local expressions and candidate strings for one validation request and is then terminated. No storage database, server API, telemetry path, or remote schema resolver is used.
+3 -3
View File
@@ -2,8 +2,8 @@
Schema sources, instances, diagnostics, comparisons, and generated samples stay in page memory. There are no accounts, analytics, telemetry, persistence, remote imports, or runtime third-party assets. Explicit source links are normal navigation only. Clearing or closing the page releases application references but cannot promise forensic erasure from browser or operating-system memory. Schema sources, instances, diagnostics, comparisons, and generated samples stay in page memory. There are no accounts, analytics, telemetry, persistence, remote imports, or runtime third-party assets. Explicit source links are normal navigation only. Clearing or closing the page releases application references but cannot promise forensic erasure from browser or operating-system memory.
Each source is limited to 2 MiB of text; a workspace is limited to 20 documents and 8 MiB. JSON/YAML trees are capped at 25,000 values, 48 levels, and 2,000 entries in one collection. XML is capped at 25,000 elements and 48 levels. References, samples, instances, and diagnostics have separate caps. File byte gates are deliberately conservative before `File.text()` decoding. Each source is limited to 2 MiB of text; a workspace is limited to 20 documents and 8 MiB. JSON/YAML trees are capped at 25,000 values, 48 levels, and 2,000 entries in one collection. XML is capped at 25,000 elements and 48 levels. References, instances, and diagnostics have separate caps. A shared sample budget is limited to 50,000 monotonic work steps, exactly 2,000 generated JSON values or XML elements, exactly 20 generated nesting levels, 512 KiB of aggregate derived text, 1,024 UTF-16 code units per copied literal without splitting surrogate pairs, and 2 MiB of serialized output. Reusing a local definition consumes the same aggregate counters on every attempt and generated occurrence; failed heuristic alternatives never refund work. Reaching the work ceiling refuses the generation operation, so exhaustion cannot be mistaken for a viable choice or skip a later mandatory constraint. File byte gates are deliberately conservative before `File.text()` decoding.
Prototype-sensitive JSON keys, cyclic YAML aliases, NUL input, DTD/entity declarations, absolute/remote/escaping references, and executable schema extensions are rejected. Schematron expressions and imported XML are never executed. JSON Schema formats are annotations, and regex-bearing schema keywords are not executed. The focused validator interprets eligible schemas without dynamic code generation, remote loading, custom code, or `unsafe-eval`; work and diagnostic counts are capped. Prototype-sensitive JSON keys, cyclic YAML aliases, NUL input, DTD/entity declarations, absolute/remote/escaping references, and executable schema extensions are rejected. Schematron expressions and imported XML are never executed. JSON Schema formats are annotations. Regex-bearing keywords are evaluated in a fresh worker that is terminated on completion or after one second; expression count and length, candidate count, and total pair evaluations are capped before dispatch. The focused validator interprets eligible schemas without dynamic code generation, remote loading, custom code, or `unsafe-eval`; work and diagnostic counts are capped.
Sample generation and compatibility results are review aids. A generated document is not guaranteed to satisfy every constraint, and an absence of reported changes does not prove compatibility. JSON validation requires a single declared draft and uses local workspace filenames rather than identifier URIs. Named anchors, nested identifier scopes, dynamic/recursive references, unevaluated keywords, regular expressions, and full meta-schema validation are outside v0.1.0. XSD, Relax NG, and Schematron instance validation is also outside v0.1.0; OpenAPI inspection is not a full conformance certification. Sample generation and compatibility results are review aids. A generated document is not guaranteed to satisfy every constraint, and an absence of reported changes does not prove compatibility. Generation refuses a definitely impossible selected `false` JSON Schema branch but does not prove broader satisfiability. JSON validation requires a single declared draft and uses local workspace filenames rather than identifier URIs. Named anchors, nested identifier scopes, dynamic/recursive references, unevaluated keywords, and full meta-schema validation remain outside the focused subset. XSD, Relax NG, and Schematron instance validation is also outside the current scope; OpenAPI inspection is not a full conformance certification.
+1 -1
View File
@@ -1,5 +1,5 @@
const CACHE_PREFIX = "schema-tools-shell-"; const CACHE_PREFIX = "schema-tools-shell-";
const CACHE_NAME = CACHE_PREFIX + "0.1.0"; const CACHE_NAME = CACHE_PREFIX + "0.2.0";
const CORE = ["./", "./manifest.webmanifest", "./favicon.svg"]; const CORE = ["./", "./manifest.webmanifest", "./favicon.svg"];
self.addEventListener("install", (event) => { self.addEventListener("install", (event) => {
event.waitUntil( event.waitUntil(
+16 -1
View File
@@ -3,7 +3,7 @@
"schemaVersion": 1, "schemaVersion": 1,
"id": "de.add-ideas.schema-tools", "id": "de.add-ideas.schema-tools",
"name": "Schema Tools", "name": "Schema Tools",
"version": "0.1.0", "version": "0.2.0",
"description": "Inspect, validate, compare, and derive schema examples locally.", "description": "Inspect, validate, compare, and derive schema examples locally.",
"entry": "./", "entry": "./",
"icon": "./favicon.svg", "icon": "./favicon.svg",
@@ -21,6 +21,21 @@
"crossOriginIsolated": false, "crossOriginIsolated": false,
"topLevelContext": false "topLevelContext": false
}, },
"io": {
"accepts": [
{ "mediaType": "application/schema+json", "extensions": [".json"] },
{ "mediaType": "application/yaml", "extensions": [".yaml", ".yml"] },
{
"mediaType": "application/xml",
"extensions": [".xsd", ".rng", ".sch", ".xml"]
}
],
"produces": [
{ "mediaType": "application/json", "extensions": [".json"] },
{ "mediaType": "application/xml", "extensions": [".xml"] }
]
},
"capabilities": { "required": [], "optional": ["workers"] },
"privacy": { "privacy": {
"processing": "local", "processing": "local",
"fileUploads": true, "fileUploads": true,
+16 -17
View File
@@ -5,7 +5,7 @@ import {
compareSchemas, compareSchemas,
generateSample, generateSample,
inspectWorkspace, inspectWorkspace,
validateJsonInstance, validateJsonInstanceSafe,
type Diagnostic, type Diagnostic,
type SampleResult, type SampleResult,
type SchemaChange, type SchemaChange,
@@ -215,9 +215,9 @@ export function Workbench() {
setDocuments(next); setDocuments(next);
setSelected(Math.min(selected, next.length - 1)); setSelected(Math.min(selected, next.length - 1));
}; };
const validate = () => { const validate = async () => {
try { try {
const result = validateJsonInstance(report, instance); const result = await validateJsonInstanceSafe(report, instance);
setValidation(result.diagnostics); setValidation(result.diagnostics);
setError(""); setError("");
} catch (reason) { } catch (reason) {
@@ -276,7 +276,8 @@ export function Workbench() {
<span className="capability focused">focused validation</span> <span className="capability focused">focused validation</span>
<p> <p>
CSP-safe Draft 6/7, 2019-09, and 2020-12 assertion subset, with CSP-safe Draft 6/7, 2019-09, and 2020-12 assertion subset, with
bounded local references. Regex-bearing keywords are not executed. bounded local references. Regex-bearing keywords run in a
disposable, deadline-limited worker.
</p> </p>
</article> </article>
<article> <article>
@@ -317,15 +318,14 @@ export function Workbench() {
<section className="panel workspace"> <section className="panel workspace">
<div <div
className="workspace-tabs" className="workspace-tabs"
role="tablist" role="group"
aria-label="Schema workbench views" aria-label="Schema workbench views"
> >
{tabs.map((item) => ( {tabs.map((item) => (
<button <button
key={item.id} key={item.id}
type="button" type="button"
role="tab" aria-pressed={tab === item.id}
aria-selected={tab === item.id}
onClick={() => setTab(item.id)} onClick={() => setTab(item.id)}
> >
{item.label} {item.label}
@@ -339,7 +339,7 @@ export function Workbench() {
)} )}
{tab === "workspace" && ( {tab === "workspace" && (
<div className="stack" role="tabpanel"> <div className="stack">
<div className="actions"> <div className="actions">
<label className="button file-button"> <label className="button file-button">
Open local schemas Open local schemas
@@ -362,15 +362,14 @@ export function Workbench() {
</div> </div>
<div <div
className="document-tabs" className="document-tabs"
role="tablist" role="group"
aria-label="Workspace documents" aria-label="Workspace documents"
> >
{documents.map((item, index) => ( {documents.map((item, index) => (
<button <button
key={`${item.name}-${index}`} key={`${item.name}-${index}`}
type="button" type="button"
role="tab" aria-pressed={index === selected}
aria-selected={index === selected}
onClick={() => setSelected(index)} onClick={() => setSelected(index)}
> >
{item.name || `Document ${index + 1}`} {item.name || `Document ${index + 1}`}
@@ -451,15 +450,15 @@ export function Workbench() {
)} )}
{tab === "validate" && ( {tab === "validate" && (
<div className="editor-grid" role="tabpanel"> <div className="editor-grid">
<div className="stack"> <div className="stack">
<div> <div>
<p className="eyebrow">Bounded instance check</p> <p className="eyebrow">Bounded instance check</p>
<h2>Validate JSON locally</h2> <h2>Validate JSON locally</h2>
<p className="muted"> <p className="muted">
Available only when the entry is JSON Schema. Formats are Available only when the entry is JSON Schema. Formats are
annotations; schemas containing pattern or patternProperties annotations; pattern and patternProperties checks run in an
are refused rather than risking unbounded regex execution. isolated worker with count, size, and time ceilings.
</p> </p>
</div> </div>
<label className="field"> <label className="field">
@@ -485,7 +484,7 @@ export function Workbench() {
)} )}
{tab === "sample" && ( {tab === "sample" && (
<div className="editor-grid" role="tabpanel"> <div className="editor-grid">
<div className="stack"> <div className="stack">
<div> <div>
<p className="eyebrow">Bounded derivation</p> <p className="eyebrow">Bounded derivation</p>
@@ -538,7 +537,7 @@ export function Workbench() {
)} )}
{tab === "references" && ( {tab === "references" && (
<div className="stack" role="tabpanel"> <div className="stack">
<div> <div>
<p className="eyebrow">No network resolution</p> <p className="eyebrow">No network resolution</p>
<h2>Local reference graph</h2> <h2>Local reference graph</h2>
@@ -588,7 +587,7 @@ export function Workbench() {
)} )}
{tab === "compare" && ( {tab === "compare" && (
<div className="stack" role="tabpanel"> <div className="stack">
<div> <div>
<p className="eyebrow">Conservative signals</p> <p className="eyebrow">Conservative signals</p>
<h2>Compare two schema revisions</h2> <h2>Compare two schema revisions</h2>
+865 -141
View File
File diff suppressed because it is too large Load Diff
+35
View File
@@ -0,0 +1,35 @@
interface RegexRequest {
id: number;
patterns: string[];
candidates: string[];
}
interface RegexResponse {
id: number;
matches?: number[][];
error?: string;
}
self.addEventListener("message", (event: MessageEvent<RegexRequest>) => {
const { id, patterns, candidates } = event.data;
try {
const matches = patterns.map((source) => {
const expression = new RegExp(source, "u");
const matching: number[] = [];
for (let index = 0; index < candidates.length; index += 1) {
expression.lastIndex = 0;
if (expression.test(candidates[index]!)) matching.push(index);
}
return matching;
});
self.postMessage({ id, matches } satisfies RegexResponse);
} catch (reason) {
self.postMessage({
id,
error:
reason instanceof Error
? reason.message
: "A schema regular expression could not be evaluated.",
} satisfies RegexResponse);
}
});
+105
View File
@@ -0,0 +1,105 @@
export interface RegexEvaluation {
pattern: string;
matches: ReadonlySet<string>;
}
export interface RegexBatchOptions {
deadlineMs?: number;
}
export type RegexBatchRunner = (
patterns: readonly string[],
candidates: readonly string[],
options?: RegexBatchOptions,
) => Promise<ReadonlyMap<string, ReadonlySet<string>>>;
interface RegexResponse {
id: number;
matches?: number[][];
error?: string;
}
let requestSequence = 0;
/**
* Evaluate untrusted JSON Schema expressions away from the UI thread. A worker
* is terminated after every request, so a timed-out expression cannot keep
* consuming CPU or retain inspected data.
*/
export const runRegexBatchInWorker: RegexBatchRunner = (
patterns,
candidates,
options = {},
) =>
new Promise((resolve, reject) => {
const worker = new Worker(new URL("./regex-worker.ts", import.meta.url), {
type: "module",
name: "schema-regex-evaluator",
});
const id = ++requestSequence;
const deadlineMs = Math.max(
50,
Math.min(options.deadlineMs ?? 1_000, 5_000),
);
let settled = false;
const finish = (operation: () => void) => {
if (settled) return;
settled = true;
clearTimeout(timer);
worker.terminate();
operation();
};
const timer = setTimeout(
() =>
finish(() =>
reject(
new RangeError(
`Schema regular-expression evaluation exceeded its ${deadlineMs}-millisecond safety limit.`,
),
),
),
deadlineMs,
);
worker.addEventListener("error", (event) => {
finish(() =>
reject(new Error(event.message || "Schema regex worker failed.")),
);
});
worker.addEventListener("message", (event: MessageEvent<RegexResponse>) => {
if (event.data.id !== id) return;
if (event.data.error) {
finish(() =>
reject(
new SyntaxError(
`Invalid or unsupported JSON Schema regular expression: ${event.data.error}`,
),
),
);
return;
}
const rows = event.data.matches;
if (!rows || rows.length !== patterns.length) {
finish(() =>
reject(new Error("Schema regex worker returned an invalid result.")),
);
return;
}
finish(() => {
const output = new Map<string, ReadonlySet<string>>();
rows.forEach((indexes, patternIndex) => {
const values = new Set<string>();
for (const candidateIndex of indexes) {
const value = candidates[candidateIndex];
if (value !== undefined) values.add(value);
}
output.set(patterns[patternIndex]!, values);
});
resolve(output);
});
});
worker.postMessage({
id,
patterns: [...patterns],
candidates: [...candidates],
});
});
+2 -2
View File
@@ -207,8 +207,8 @@ pre {
flex-wrap: nowrap; flex-wrap: nowrap;
padding-bottom: 0.2rem; padding-bottom: 0.2rem;
} }
.workspace-tabs button[aria-selected="true"], .workspace-tabs button[aria-pressed="true"],
.document-tabs button[aria-selected="true"] { .document-tabs button[aria-pressed="true"] {
border-color: var(--toolbox-accent); border-color: var(--toolbox-accent);
background: var(--toolbox-accent); background: var(--toolbox-accent);
color: var(--toolbox-accent-contrast); color: var(--toolbox-accent-contrast);
+31 -1
View File
@@ -3,7 +3,7 @@
"schemaVersion": 1, "schemaVersion": 1,
"id": "de.add-ideas.schema-tools", "id": "de.add-ideas.schema-tools",
"name": "Schema Tools", "name": "Schema Tools",
"version": "0.1.0", "version": "0.2.0",
"description": "Inspect, validate, compare, and derive schema examples locally.", "description": "Inspect, validate, compare, and derive schema examples locally.",
"entry": "./", "entry": "./",
"icon": "./favicon.svg", "icon": "./favicon.svg",
@@ -21,6 +21,36 @@
"crossOriginIsolated": false, "crossOriginIsolated": false,
"topLevelContext": false "topLevelContext": false
}, },
"io": {
"accepts": [
{
"mediaType": "application/schema+json",
"extensions": [".json"]
},
{
"mediaType": "application/yaml",
"extensions": [".yaml", ".yml"]
},
{
"mediaType": "application/xml",
"extensions": [".xsd", ".rng", ".sch", ".xml"]
}
],
"produces": [
{
"mediaType": "application/json",
"extensions": [".json"]
},
{
"mediaType": "application/xml",
"extensions": [".xml"]
}
]
},
"capabilities": {
"required": [],
"optional": ["workers"]
},
"privacy": { "privacy": {
"processing": "local", "processing": "local",
"fileUploads": true, "fileUploads": true,
+1 -1
View File
@@ -1 +1 @@
export const APP_VERSION = "0.1.0"; export const APP_VERSION = "0.2.0";
+3 -3
View File
@@ -36,10 +36,10 @@ test("validates and traces a supplied local JSON Schema reference", async ({
}) => { }) => {
const external = await localOnly(page); const external = await localOnly(page);
await page.goto("/deep/nested/schema/"); await page.goto("/deep/nested/schema/");
await page.getByRole("tab", { name: "Validate" }).click(); await page.getByRole("button", { name: "Validate" }).click();
await page.getByRole("button", { name: "Validate instance" }).click(); await page.getByRole("button", { name: "Validate instance" }).click();
await expect(page.getByText(/Instance is valid/u)).toBeVisible(); await expect(page.getByText(/Instance is valid/u)).toBeVisible();
await page.getByRole("tab", { name: "References" }).click(); await page.getByRole("button", { name: "References" }).click();
await expect( await expect(
page.getByText("address.schema.json#/$defs/address", { exact: true }), page.getByText("address.schema.json#/$defs/address", { exact: true }),
).toBeVisible(); ).toBeVisible();
@@ -70,7 +70,7 @@ test("serves release identity and hardened headers", async ({ request }) => {
const manifest = await request.get("/deep/nested/schema/toolbox-app.json"); const manifest = await request.get("/deep/nested/schema/toolbox-app.json");
await expect(manifest.json()).resolves.toMatchObject({ await expect(manifest.json()).resolves.toMatchObject({
id: "de.add-ideas.schema-tools", id: "de.add-ideas.schema-tools",
version: "0.1.0", version: "0.2.0",
entry: "./", entry: "./",
privacy: { processing: "local", telemetry: false }, privacy: { processing: "local", telemetry: false },
}); });
+18
View File
@@ -0,0 +1,18 @@
import { expect, test } from "@playwright/test";
test("keeps the primary workspace inside a narrow viewport", async ({
page,
}) => {
await page.goto("/deep/nested/schema/");
await expect(page.locator("main").first()).toBeVisible();
await expect(
page.locator("main .loading, main .workbench-loading"),
).toHaveCount(0);
const widths = await page.evaluate(() => ({
content: document.documentElement.scrollWidth,
viewport: document.documentElement.clientWidth,
}));
expect(widths.viewport).toBeLessThanOrEqual(430);
expect(widths.content).toBeLessThanOrEqual(widths.viewport + 1);
});
+1 -1
View File
@@ -20,7 +20,7 @@ describe("Schema Tools", () => {
); );
expect(screen.getByText("focused validation")).toBeVisible(); expect(screen.getByText("focused validation")).toBeVisible();
expect(screen.getAllByText("structural only")).toHaveLength(2); expect(screen.getAllByText("structural only")).toHaveLength(2);
await userEvent.click(screen.getByRole("tab", { name: "Validate" })); await userEvent.click(screen.getByRole("button", { name: "Validate" }));
await userEvent.click( await userEvent.click(
screen.getByRole("button", { name: "Validate instance" }), screen.getByRole("button", { name: "Validate instance" }),
); );
+771 -2
View File
@@ -1,10 +1,12 @@
import { describe, expect, it } from "vitest"; import { describe, expect, it } from "vitest";
import { import {
SCHEMA_LIMITS,
compareSchemas, compareSchemas,
generateSample, generateSample,
inspectWorkspace, inspectWorkspace,
parseSchemaDocument, parseSchemaDocument,
validateJsonInstance, validateJsonInstance,
validateJsonInstanceSafe,
} from "../../src/schema/model"; } from "../../src/schema/model";
const entry = { const entry = {
@@ -36,7 +38,148 @@ const support = {
}), }),
}; };
function nestedJsonSchema(levels: number): object {
let schema: object = { const: "leaf" };
for (let level = 1; level < levels; level += 1)
schema = {
type: "object",
required: ["child"],
properties: { child: schema },
};
return schema;
}
function jsonValueDepth(value: unknown): number {
if (!value || typeof value !== "object") return 1;
const children = Object.values(value);
return 1 + (children.length ? Math.max(...children.map(jsonValueDepth)) : 0);
}
function xsdChain(levels: number): string {
const types = Array.from({ length: levels - 1 }, (_, index) => {
const number = index + 1;
const childType = number === levels - 1 ? "xs:string" : `Type${number + 1}`;
return `<xs:complexType name="Type${number}"><xs:sequence><xs:element name="level${number + 1}" type="${childType}"/></xs:sequence></xs:complexType>`;
}).join("");
return `<xs:schema xmlns:xs="http://www.w3.org/2001/XMLSchema">${types}<xs:element name="level1" type="Type1"/></xs:schema>`;
}
function relaxNgChain(levels: number): string {
let pattern = "<text/>";
for (let level = levels; level >= 1; level -= 1)
pattern = `<element name="level${level}"><group>${pattern}</group></element>`;
return `<grammar xmlns="http://relaxng.org/ns/structure/1.0"><start>${pattern}</start></grammar>`;
}
function hasUnpairedSurrogate(value: string): boolean {
for (let index = 0; index < value.length; index += 1) {
const code = value.charCodeAt(index);
if (code >= 0xd800 && code <= 0xdbff) {
const next = value.charCodeAt(index + 1);
if (next < 0xdc00 || next > 0xdfff) return true;
index += 1;
} else if (code >= 0xdc00 && code <= 0xdfff) return true;
}
return false;
}
const amplifiedChoiceSupport = {
name: "choices.json",
source: JSON.stringify({
$defs: {
impossible: {
anyOf: Array.from({ length: 600 }, () => false),
},
amplified: {
anyOf: Array.from({ length: 100 }, () => ({
$ref: "#/$defs/impossible",
})),
},
},
}),
};
function captureError(run: () => unknown): Error {
try {
run();
} catch (error) {
if (error instanceof Error) return error;
throw error;
}
throw new Error("Expected operation to throw.");
}
describe("schema workspace", () => { describe("schema workspace", () => {
it("validates pattern and patternProperties through a bounded batch runner", async () => {
const workspace = inspectWorkspace([
{
name: "pattern.schema.json",
source: JSON.stringify({
type: "object",
propertyNames: { pattern: "^[a-z-]+$" },
properties: {
label: { type: "string", pattern: "^ok(?:-|$)" },
},
patternProperties: {
"^x-": { type: "integer", minimum: 0 },
},
additionalProperties: false,
}),
},
]);
const runner = async (
patterns: readonly string[],
candidates: readonly string[],
) =>
new Map(
patterns.map((source) => {
const expression = new RegExp(source, "u");
return [
source,
new Set(
candidates.filter((candidate) => expression.test(candidate)),
),
] as const;
}),
);
expect(
(
await validateJsonInstanceSafe(
workspace,
JSON.stringify({ label: "ok-value", "x-count": 2 }),
workspace.entry,
runner,
)
).valid,
).toBe(true);
const invalid = await validateJsonInstanceSafe(
workspace,
JSON.stringify({ label: "bad", "x-count": "two", Other: true }),
workspace.entry,
runner,
);
expect(invalid.valid).toBe(false);
expect(invalid.diagnostics.map((item) => item.message).join("\n")).toMatch(
/pattern.*does not match|type.*integer|additionalProperties|false schema/iu,
);
});
it("refuses synchronous regex validation instead of executing on the caller thread", () => {
const workspace = inspectWorkspace([
{
name: "pattern.schema.json",
source: JSON.stringify({ type: "string", pattern: "^(a+)+$" }),
},
]);
const result = validateJsonInstance(workspace, JSON.stringify("aaaa"));
expect(result.valid).toBe(false);
expect(result.diagnostics[0]?.message).toMatch(
/bounded asynchronous validation|isolated worker/iu,
);
});
it("resolves local references, generates a sample, and validates instances", () => { it("resolves local references, generates a sample, and validates instances", () => {
const workspace = inspectWorkspace([entry, support], entry.name); const workspace = inspectWorkspace([entry, support], entry.name);
expect(workspace.references).toEqual([ expect(workspace.references).toEqual([
@@ -60,6 +203,299 @@ describe("schema workspace", () => {
expect(invalid.diagnostics[0]?.message).toContain("required"); expect(invalid.diagnostics[0]?.message).toContain("required");
}); });
it("bounds repeated large literal samples reached through local references", () => {
const properties = Object.fromEntries(
Array.from({ length: 100 }, (_, index) => [
`value${index}`,
{ $ref: "literal.json#/$defs/large" },
]),
);
const workspace = inspectWorkspace([
{
name: "root.json",
source: JSON.stringify({
type: "object",
required: Object.keys(properties),
properties,
}),
},
{
name: "literal.json",
source: JSON.stringify({
$defs: { large: { default: "x".repeat(100_000) } },
}),
},
]);
const sample = generateSample(workspace);
const values = Object.values(JSON.parse(sample.output) as object);
expect(sample.output.length).toBeLessThanOrEqual(
SCHEMA_LIMITS.sampleOutputChars,
);
expect(values).toHaveLength(100);
expect(
values.every(
(value) => String(value).length <= SCHEMA_LIMITS.sampleValueChars,
),
).toBe(true);
expect(sample.notices.join("\n")).toMatch(/truncated.*safety bound/iu);
});
it("applies the exact JSON node budget to copied literal collections", () => {
const workspace = inspectWorkspace([
{
name: "literal-array.json",
source: JSON.stringify({
default: Array.from({ length: 100 }, () =>
Array.from({ length: 20 }, () => null),
),
}),
},
]);
const sample = generateSample(workspace);
const value = JSON.parse(sample.output) as unknown;
const countNodes = (item: unknown): number =>
item && typeof item === "object"
? 1 +
Object.values(item).reduce((sum, child) => sum + countNodes(child), 0)
: 1;
expect(countNodes(value)).toBe(SCHEMA_LIMITS.sampleNodes);
expect(sample.notices.join("\n")).toMatch(/node.*safety bound/iu);
});
it("monotonically bounds amplified JSON choice attempts through reused refs", () => {
const properties = Object.fromEntries(
Array.from({ length: 100 }, (_, index) => [
`value${index}`,
{ $ref: "choices.json#/$defs/value" },
]),
);
const workspace = inspectWorkspace([
{
name: "root.json",
source: JSON.stringify({
type: "object",
required: Object.keys(properties),
properties,
}),
},
{
name: "choices.json",
source: JSON.stringify({
$defs: {
value: {
anyOf: [
...Array.from({ length: 600 }, () => false),
{ const: "viable" },
],
},
},
}),
},
]);
const started = performance.now();
const error = captureError(() => generateSample(workspace));
const elapsed = performance.now() - started;
expect(error.message).toMatch(/sample budget was exhausted/iu);
expect(error.message).not.toMatch(/first viable/iu);
expect(elapsed).toBeLessThan(2_000);
});
it("never treats exhausted all-impossible anyOf or oneOf branches as viable", () => {
for (const keyword of ["anyOf", "oneOf"] as const) {
const workspace = inspectWorkspace([
{
name: `${keyword}.json`,
source: JSON.stringify({
[keyword]: Array.from({ length: 100 }, () => ({
$ref: "choices.json#/$defs/impossible",
})),
}),
},
amplifiedChoiceSupport,
]);
const error = captureError(() => generateSample(workspace));
expect(error.message).toMatch(/sample budget was exhausted/iu);
expect(error.message).not.toMatch(/first viable/iu);
}
});
it("refuses a partial mandatory allOf when prior work exhausts the budget", () => {
const properties = Object.fromEntries(
Array.from({ length: 100 }, (_, index) => [
`value${index}`,
{ $ref: "choices.json#/$defs/amplified" },
]),
);
const workspace = inspectWorkspace([
{
name: "all-of.json",
source: JSON.stringify({
allOf: [
{
type: "object",
required: Object.keys(properties),
properties,
},
false,
],
}),
},
amplifiedChoiceSupport,
]);
expect(() => generateSample(workspace)).toThrow(
/sample budget was exhausted/iu,
);
});
it("propagates optional-property exhaustion before later required constraints", () => {
for (const requiredSchema of [{ const: "required" }, false] as const) {
const workspace = inspectWorkspace([
{
name: "optional-before-required.json",
source: JSON.stringify({
type: "object",
required: ["required"],
properties: {
optional: { $ref: "choices.json#/$defs/amplified" },
required: requiredSchema,
},
}),
},
amplifiedChoiceSupport,
]);
expect(() => generateSample(workspace)).toThrow(
/sample budget was exhausted/iu,
);
}
});
it("propagates work exhaustion from a required array item", () => {
const workspace = inspectWorkspace([
{
name: "required-item.json",
source: JSON.stringify({
type: "array",
minItems: 1,
items: { $ref: "choices.json#/$defs/amplified" },
}),
},
amplifiedChoiceSupport,
]);
expect(() => generateSample(workspace)).toThrow(
/sample budget was exhausted/iu,
);
});
it("charges cached wide JSON property visits on every reused schema", () => {
const wideProperties = Object.fromEntries(
Array.from({ length: 2_000 }, (_, index) => [
`optional${index}`,
{ type: "string" },
]),
);
const workspace = inspectWorkspace([
{
name: "wide-references.json",
source: JSON.stringify({
allOf: Array.from({ length: 2_000 }, () => ({
$ref: "wide.json#/$defs/wide",
})),
}),
},
{
name: "wide.json",
source: JSON.stringify({
$defs: {
wide: { type: "object", properties: wideProperties },
},
}),
},
]);
const started = performance.now();
const error = captureError(() => generateSample(workspace));
expect(error.message).toMatch(/sample budget was exhausted/iu);
expect(performance.now() - started).toBeLessThan(2_000);
});
it("admits exactly 20 generated JSON levels and omits level 21", () => {
const exact = inspectWorkspace([
{
name: "depth-20.json",
source: JSON.stringify(nestedJsonSchema(20)),
},
]);
const exactSample = generateSample(exact);
expect(jsonValueDepth(JSON.parse(exactSample.output))).toBe(20);
expect(exactSample.notices.join("\n")).not.toMatch(/level safety bound/iu);
const excessive = inspectWorkspace([
{
name: "depth-21.json",
source: JSON.stringify(nestedJsonSchema(21)),
},
]);
const boundedSample = generateSample(excessive);
expect(jsonValueDepth(JSON.parse(boundedSample.output))).toBe(20);
expect(boundedSample.notices.join("\n")).toMatch(/level safety bound/iu);
});
it("truncates JSON literals without splitting surrogate pairs", () => {
const value = `a${"😀".repeat(600)}`;
const workspace = inspectWorkspace([
{
name: "unicode.json",
source: JSON.stringify({ default: value }),
},
]);
const generated = JSON.parse(generateSample(workspace).output) as string;
expect(generated.length).toBeLessThanOrEqual(
SCHEMA_LIMITS.sampleValueChars,
);
expect(hasUnpairedSurrogate(generated)).toBe(false);
});
it("refuses to claim a sample for the always-invalid false schema", () => {
const workspace = inspectWorkspace([
{ name: "impossible.json", source: "false" },
]);
expect(() => generateSample(workspace)).toThrow(/no valid sample/iu);
});
it("refuses false schemas reached through references and required combiners", () => {
const referenced = inspectWorkspace([
{ name: "root.json", source: JSON.stringify({ $ref: "defs.json" }) },
{ name: "defs.json", source: "false" },
]);
expect(() => generateSample(referenced)).toThrow(/no valid sample/iu);
const combined = inspectWorkspace([
{
name: "combined.json",
source: JSON.stringify({ allOf: [{ type: "object" }, false] }),
},
]);
expect(() => generateSample(combined)).toThrow(/no valid sample/iu);
});
it("skips impossible alternatives when a viable anyOf sample exists", () => {
const workspace = inspectWorkspace([
{
name: "choice.json",
source: JSON.stringify({
anyOf: [false, { type: "string", const: "viable" }],
}),
},
]);
expect(JSON.parse(generateSample(workspace).output)).toBe("viable");
});
it("blocks remote and missing references without attempting resolution", () => { it("blocks remote and missing references without attempting resolution", () => {
const workspace = inspectWorkspace([ const workspace = inspectWorkspace([
{ {
@@ -86,7 +522,7 @@ describe("schema workspace", () => {
); );
}); });
it("refuses executable regex keywords in the bounded validator", () => { it("routes executable regex keywords away from the synchronous validator", () => {
const workspace = inspectWorkspace([ const workspace = inspectWorkspace([
{ {
name: "pattern.json", name: "pattern.json",
@@ -95,7 +531,9 @@ describe("schema workspace", () => {
]); ]);
const result = validateJsonInstance(workspace, JSON.stringify("aaaa")); const result = validateJsonInstance(workspace, JSON.stringify("aaaa"));
expect(result.valid).toBe(false); expect(result.valid).toBe(false);
expect(result.diagnostics[0]?.message).toMatch(/pattern.*not executed/iu); expect(result.diagnostics[0]?.message).toMatch(
/regular expressions.*bounded asynchronous validation/iu,
);
}); });
it("also refuses regex and dynamic-reference keywords in supplied reference documents", () => { it("also refuses regex and dynamic-reference keywords in supplied reference documents", () => {
@@ -215,6 +653,154 @@ describe("schema languages", () => {
expect(sample.notices[0]).toContain("Heuristic XSD"); expect(sample.notices[0]).toContain("Heuristic XSD");
}); });
it("applies the aggregate text budget to repeated XSD type literals", () => {
const branches = Array.from(
{ length: 50 },
(_, index) => `<xs:element name="branch${index}" type="Branch"/>`,
).join("");
const leaves = Array.from(
{ length: 50 },
(_, index) => `<xs:element name="item${index}" type="LargeText"/>`,
).join("");
const workspace = inspectWorkspace([
{
name: "amplified.xsd",
source: `<xs:schema xmlns:xs="http://www.w3.org/2001/XMLSchema"><xs:simpleType name="LargeText"><xs:restriction base="xs:string"><xs:enumeration value="${"x".repeat(SCHEMA_LIMITS.sampleValueChars)}"/></xs:restriction></xs:simpleType><xs:complexType name="Branch"><xs:sequence>${leaves}</xs:sequence></xs:complexType><xs:element name="root"><xs:complexType><xs:sequence>${branches}</xs:sequence></xs:complexType></xs:element></xs:schema>`,
},
]);
const sample = generateSample(workspace);
const parsed = new DOMParser().parseFromString(sample.output, "text/xml");
expect(parsed.querySelector("parsererror")).toBeNull();
expect(parsed.documentElement.textContent?.length ?? 0).toBeLessThanOrEqual(
SCHEMA_LIMITS.sampleTextChars,
);
expect(parsed.querySelectorAll("*").length).toBeLessThanOrEqual(
SCHEMA_LIMITS.sampleNodes,
);
expect(sample.output.length).toBeLessThanOrEqual(
SCHEMA_LIMITS.sampleOutputChars,
);
expect(sample.notices.join("\n")).toMatch(/text safety bound/iu);
});
it("linearly inspects and preindexes a large reused XSD type", () => {
const leaves = Array.from(
{ length: 20_000 },
() => `<xs:element name="leaf" type="xs:string"/>`,
).join("");
const branches = Array.from(
{ length: 50 },
(_, index) => `<xs:element name="branch${index}" type="Heavy"/>`,
).join("");
const source = `<xs:schema xmlns:xs="http://www.w3.org/2001/XMLSchema"><xs:complexType name="Heavy"><xs:sequence>${leaves}</xs:sequence></xs:complexType><xs:complexType name="Root"><xs:sequence>${branches}</xs:sequence></xs:complexType><xs:element name="root" type="Root"/></xs:schema>`;
const inspectStarted = performance.now();
const workspace = inspectWorkspace([{ name: "large-flat.xsd", source }]);
const inspectElapsed = performance.now() - inspectStarted;
const generateStarted = performance.now();
const sample = generateSample(workspace);
const generateElapsed = performance.now() - generateStarted;
const parsed = new DOMParser().parseFromString(sample.output, "text/xml");
expect(parsed.querySelector("parsererror")).toBeNull();
expect(parsed.querySelectorAll("*").length).toBeLessThanOrEqual(
SCHEMA_LIMITS.sampleNodes,
);
expect(inspectElapsed).toBeLessThan(2_000);
expect(generateElapsed).toBeLessThan(2_000);
});
it("linearly inspects a wide XSD schema container", () => {
const annotations = Array.from(
{ length: 20_000 },
() => "<xs:annotation/>",
).join("");
const source = `<xs:schema xmlns:xs="http://www.w3.org/2001/XMLSchema"><xs:element name="root"/>${annotations}</xs:schema>`;
const started = performance.now();
const workspace = inspectWorkspace([{ name: "wide-root.xsd", source }]);
const elapsed = performance.now() - started;
expect(workspace.documents.get(workspace.entry)?.language).toBe("xsd");
expect(elapsed).toBeLessThan(2_000);
});
it("admits exactly 20 generated XSD levels and omits level 21", () => {
for (const [levels, noticeExpected] of [
[20, false],
[21, true],
] as const) {
const workspace = inspectWorkspace([
{ name: `depth-${levels}.xsd`, source: xsdChain(levels) },
]);
const sample = generateSample(workspace);
const parsed = new DOMParser().parseFromString(sample.output, "text/xml");
expect(parsed.querySelector("parsererror")).toBeNull();
expect(parsed.querySelectorAll("*")).toHaveLength(20);
expect(/level safety bound/iu.test(sample.notices.join("\n"))).toBe(
noticeExpected,
);
}
});
it("keeps truncated XSD astral literals well formed", () => {
const value = `a${"😀".repeat(600)}`;
const workspace = inspectWorkspace([
{
name: "unicode.xsd",
source: `<xs:schema xmlns:xs="http://www.w3.org/2001/XMLSchema"><xs:simpleType name="Unicode"><xs:restriction base="xs:string"><xs:enumeration value="${value}"/></xs:restriction></xs:simpleType><xs:element name="root" type="Unicode"/></xs:schema>`,
},
]);
const sample = generateSample(workspace);
const parsed = new DOMParser().parseFromString(sample.output, "text/xml");
expect(parsed.querySelector("parsererror")).toBeNull();
expect(hasUnpairedSurrogate(parsed.documentElement.textContent ?? "")).toBe(
false,
);
});
it("omits duplicate and fallback-colliding XSD attributes", () => {
const workspace = inspectWorkspace([
{
name: "attributes.xsd",
source: `<xs:schema xmlns:xs="http://www.w3.org/2001/XMLSchema"><xs:complexType name="WithAttributes"><xs:attribute name="same"/><xs:attribute name="same"/><xs:attribute name="1bad"/><xs:attribute name="2bad"/></xs:complexType><xs:element name="root" type="WithAttributes"/></xs:schema>`,
},
]);
const sample = generateSample(workspace);
const parsed = new DOMParser().parseFromString(sample.output, "text/xml");
expect(parsed.querySelector("parsererror")).toBeNull();
expect(parsed.documentElement.attributes).toHaveLength(2);
expect(parsed.documentElement.hasAttribute("same")).toBe(true);
expect(parsed.documentElement.hasAttribute("attribute")).toBe(true);
expect(sample.notices.join("\n")).toMatch(/duplicate.*attribute/iu);
});
it("caches a wide inline XSD type across repeated rendering", () => {
const annotations = Array.from(
{ length: 20_000 },
() => "<xs:annotation/>",
).join("");
const branches = Array.from(
{ length: 50 },
(_, index) => `<xs:element name="branch${index}" type="Branch"/>`,
).join("");
const workspace = inspectWorkspace([
{
name: "wide-inline.xsd",
source: `<xs:schema xmlns:xs="http://www.w3.org/2001/XMLSchema"><xs:complexType name="Branch"><xs:sequence><xs:element name="leaf">${annotations}<xs:simpleType><xs:restriction base="xs:string"/></xs:simpleType></xs:element></xs:sequence></xs:complexType><xs:complexType name="Root"><xs:sequence>${branches}</xs:sequence></xs:complexType><xs:element name="root" type="Root"/></xs:schema>`,
},
]);
const started = performance.now();
const sample = generateSample(workspace);
const elapsed = performance.now() - started;
const parsed = new DOMParser().parseFromString(sample.output, "text/xml");
expect(parsed.querySelector("parsererror")).toBeNull();
expect(elapsed).toBeLessThan(2_000);
});
it("inventories Relax NG and Schematron without executing expressions", () => { it("inventories Relax NG and Schematron without executing expressions", () => {
const rng = inspectWorkspace([ const rng = inspectWorkspace([
{ {
@@ -241,6 +827,157 @@ describe("schema languages", () => {
).toBe(true); ).toBe(true);
}); });
it("retains a direct-root Relax NG element in the generated sample", () => {
const workspace = inspectWorkspace([
{
name: "direct.rng",
source: `<element xmlns="http://relaxng.org/ns/structure/1.0" name="root"><text/></element>`,
},
]);
const sample = generateSample(workspace);
const parsed = new DOMParser().parseFromString(sample.output, "text/xml");
expect(parsed.querySelector("parsererror")).toBeNull();
expect(parsed.documentElement.localName).toBe("root");
expect(parsed.documentElement.textContent).toBe("string");
});
it("never emits more than the exact Relax NG sample node budget", () => {
const repeatedElements = Array.from(
{ length: SCHEMA_LIMITS.sampleNodes },
() => `<element name="node"><text/></element>`,
).join("");
const workspace = inspectWorkspace([
{
name: "bounded.rng",
source: `<grammar xmlns="http://relaxng.org/ns/structure/1.0"><start><element name="root"><group>${repeatedElements}</group></element></start></grammar>`,
},
]);
const sample = generateSample(workspace);
const parsed = new DOMParser().parseFromString(sample.output, "text/xml");
expect(parsed.querySelector("parsererror")).toBeNull();
expect(parsed.querySelectorAll("*")).toHaveLength(
SCHEMA_LIMITS.sampleNodes,
);
});
it("applies the aggregate text budget through repeated Relax NG refs", () => {
const references = Array.from(
{ length: SCHEMA_LIMITS.sampleNodes },
() => `<ref name="large"/>`,
).join("");
const workspace = inspectWorkspace([
{
name: "text-budget.rng",
source: `<grammar xmlns="http://relaxng.org/ns/structure/1.0"><define name="large"><value>${"x".repeat(SCHEMA_LIMITS.sampleValueChars)}</value></define><start><element name="root"><group>${references}</group></element></start></grammar>`,
},
]);
const sample = generateSample(workspace);
const parsed = new DOMParser().parseFromString(sample.output, "text/xml");
expect(parsed.querySelector("parsererror")).toBeNull();
expect(parsed.documentElement.textContent?.length ?? 0).toBeLessThanOrEqual(
SCHEMA_LIMITS.sampleTextChars,
);
expect(sample.notices.join("\n")).toMatch(/text safety bound/iu);
});
it("bounds amplified Relax NG pattern visits independently of output", () => {
const width = 300;
const emptyPatterns = Array.from({ length: width }, () => "<empty/>").join(
"",
);
const references = Array.from(
{ length: width },
() => `<ref name="fanout"/>`,
).join("");
const workspace = inspectWorkspace([
{
name: "amplified-work.rng",
source: `<grammar xmlns="http://relaxng.org/ns/structure/1.0"><define name="fanout"><group>${emptyPatterns}</group></define><start><element name="root"><group>${references}</group></element></start></grammar>`,
},
]);
const started = performance.now();
const error = captureError(() => generateSample(workspace));
const elapsed = performance.now() - started;
expect(error.message).toMatch(/sample budget was exhausted/iu);
expect(elapsed).toBeLessThan(2_000);
});
it("caches wide reused Relax NG pattern containers", () => {
const ignored = Array.from({ length: 19_000 }, () => "<empty/>").join("");
const references = Array.from(
{ length: 1_000 },
() => '<ref name="wide"/>',
).join("");
const workspace = inspectWorkspace([
{
name: "wide-reused.rng",
source: `<grammar xmlns="http://relaxng.org/ns/structure/1.0"><define name="wide"><choice><empty/></choice>${ignored}</define><start><element name="root"><group>${references}</group></element></start></grammar>`,
},
]);
const started = performance.now();
const sample = generateSample(workspace);
const elapsed = performance.now() - started;
const parsed = new DOMParser().parseFromString(sample.output, "text/xml");
expect(parsed.querySelector("parsererror")).toBeNull();
expect(parsed.documentElement.localName).toBe("root");
expect(elapsed).toBeLessThan(2_000);
});
it("counts generated Relax NG levels rather than wrapper patterns", () => {
for (const [levels, noticeExpected] of [
[20, false],
[21, true],
] as const) {
const workspace = inspectWorkspace([
{ name: `depth-${levels}.rng`, source: relaxNgChain(levels) },
]);
const sample = generateSample(workspace);
const parsed = new DOMParser().parseFromString(sample.output, "text/xml");
expect(parsed.querySelector("parsererror")).toBeNull();
expect(parsed.querySelectorAll("*")).toHaveLength(20);
expect(/level safety bound/iu.test(sample.notices.join("\n"))).toBe(
noticeExpected,
);
}
});
it("keeps truncated Relax NG astral literals well formed", () => {
const value = `a${"😀".repeat(600)}`;
const workspace = inspectWorkspace([
{
name: "unicode.rng",
source: `<element xmlns="http://relaxng.org/ns/structure/1.0" name="root"><value>${value}</value></element>`,
},
]);
const sample = generateSample(workspace);
const parsed = new DOMParser().parseFromString(sample.output, "text/xml");
expect(parsed.querySelector("parsererror")).toBeNull();
expect(hasUnpairedSurrogate(parsed.documentElement.textContent ?? "")).toBe(
false,
);
});
it("omits duplicate and fallback-colliding Relax NG attributes", () => {
const workspace = inspectWorkspace([
{
name: "attributes.rng",
source: `<element xmlns="http://relaxng.org/ns/structure/1.0" name="root"><attribute name="same"/><attribute name="same"/><attribute name="1bad"/><attribute name="2bad"/><text/></element>`,
},
]);
const sample = generateSample(workspace);
const parsed = new DOMParser().parseFromString(sample.output, "text/xml");
expect(parsed.querySelector("parsererror")).toBeNull();
expect(parsed.documentElement.attributes).toHaveLength(2);
expect(parsed.documentElement.hasAttribute("same")).toBe(true);
expect(parsed.documentElement.hasAttribute("attribute")).toBe(true);
expect(sample.notices.join("\n")).toMatch(/duplicate.*attribute/iu);
});
it("parses OpenAPI YAML, inventories operations, and derives component samples", () => { it("parses OpenAPI YAML, inventories operations, and derives component samples", () => {
const workspace = inspectWorkspace([ const workspace = inspectWorkspace([
{ {
@@ -274,6 +1011,38 @@ components:
name: "string", name: "string",
}); });
}); });
it("refuses an impossible OpenAPI component sample", () => {
const workspace = inspectWorkspace([
{
name: "impossible-openapi.json",
source: JSON.stringify({
openapi: "3.1.0",
info: { title: "Impossible", version: "1" },
paths: {},
components: { schemas: { Impossible: false } },
}),
},
]);
expect(() => generateSample(workspace)).toThrow(/no valid sample/iu);
});
it("applies the same 20-level depth ceiling to OpenAPI samples", () => {
const workspace = inspectWorkspace([
{
name: "deep-openapi.json",
source: JSON.stringify({
openapi: "3.1.0",
info: { title: "Deep", version: "1" },
paths: {},
components: { schemas: { Deep: nestedJsonSchema(21) } },
}),
},
]);
const sample = generateSample(workspace);
expect(jsonValueDepth(JSON.parse(sample.output))).toBe(20);
expect(sample.notices.join("\n")).toMatch(/level safety bound/iu);
});
}); });
describe("conservative comparison", () => { describe("conservative comparison", () => {