Repository navigation
feat(plan): add --only filter for bola/bfla/baseline - #21
jabrailkhalil wants to merge 2 commits into
Conversation
|
The CI workflows for the current head |
kunalKumar-13
left a comment
There was a problem hiding this comment.
looks good, tests pass and typecheck is clean. one small thing below: constructor and __proto__ get past the lookup because it reads inherited keys, so --only constructor runs an empty plan instead of showing the error.
| */ | ||
| export function parseOnlyFilter(value: string | undefined): TestKind | undefined { | ||
| if (value === undefined) return undefined; | ||
| const kind = ONLY_FILTERS[value.toLowerCase()]; |
There was a problem hiding this comment.
ONLY_FILTERS['constructor'] is Object, so this returns a function instead of throwing. an own-property check fixes it:
| const kind = ONLY_FILTERS[value.toLowerCase()]; | |
| const key = value.toLowerCase(); | |
| const kind = Object.hasOwn(ONLY_FILTERS, key) ? ONLY_FILTERS[key] : undefined; |
There was a problem hiding this comment.
Fixed in 45e179b with the own-property check you suggested. Added regression cases for constructor, proto, and uppercase CONSTRUCTOR: all three failed before the fix and now pass. All 29 tests, typecheck, and build pass. The built CLI now exits 2 with the allowed-value error for those inputs; bola/BFLA/Baseline still produce nonempty dry-run plans and exit 0. The new CI run is awaiting maintainer approval before execution: https://github.com/ScalerOpenSourceLabsOrg/authzprobe/actions/runs/36575485610. Could you approve that run?
kunalKumar-13
left a comment
There was a problem hiding this comment.
checked 45e179b. constructor, proto and CONSTRUCTOR now exit 2 with the error, and bola/bfla/baseline still plan and exit 0. 29/29, typecheck and build clean. approved the ci run too.
|
Thanks @kunalKumar-13 for checking the inherited-key fix and approving CI. I confirmed the reviewed head |
What & why
Adds the
--only <kind>CLI flag so a scan can be restricted to a single test family:bola,bfla, orbaseline. This is useful when only one class of checks is needed (e.g. baseline-only self-access validation during setup).Closes #8
Type of change
What changed
src/engine/plan.ts:PlanOptions.onlyplusparseOnlyFilter()which validates the CLI value and raises a clear error listing the allowed kinds.src/cli.ts: new--only <kind>option wired into the scan.src/engine/run.ts: passesonlythrough to the planner.tests/plan.test.ts: coverage for the filter (plan only ever contains the requested kind) and for the invalid-value error.Checklist
npm testpasses (26 tests, was 23)npm run typecheckpassesnpm run buildpasses--include-unsafeOutput
Notes for reviewers
The option is opt-in and changes nothing when omitted, so the default scan behaviour is preserved.