Repository navigation
Chore/zpl escape and cache limits - #42
Merged
Merged
Conversation
contentSpec restricts `^/~` and other non-alphanumerics at input, but ZPL-imported designs bypass that filter. Re-apply filterContent at emit time so hostile content can't smuggle command/format prefixes (^/~) or parameter separators (`,`) into the ^SN start parameter, and use the sanitised length for ^SF pad-digits so the printed value matches the FD payload. fdField on the FD side stays as belt-and-suspenders for any future spec relaxation.
UI `accept="image/*"` and `accept=".ttf,.otf"` are hints only — files arriving via drag-drop or programmatic upload bypass them. Add a 2 MiB cap per image and 4 MiB cap per font, plus MIME / extension checks at the loader boundary. Bounds the localStorage quota damage from a single oversized drop and prevents non-image / non-font bytes from being persisted as data-URLs.
Both imageCache and fontCache had identical `for (let i = 0; i < length; i++) … try JSON.parse` hydration loops and identical try/setItem/catch quota guards. Extract into localStorageBucket: `hydrateLocalStoragePrefix` and `safeLocalStorageSet`. Each cache module now expresses its concern (image/font specifics) without re-implementing the storage plumbing.
Forward only well-defined entries to the consumer. `getItem` returns null for removed keys (the test-env localStorage shim retains tombstones after `clear`); skipping early avoids forwarding JS `null` typed as T.
There was a problem hiding this comment.
Code Review
This pull request centralizes localStorage management into a new utility module, localStorageBucket.ts, which handles quota errors and hydration logic for font and image caches. It also introduces file size and type validation for font (4MB) and image (2MB) uploads to prevent cache bloat. Additionally, ZPL generation for serial objects is improved by re-filtering content at emit time to prevent command injection from imported designs. Feedback focused on improving the robustness of the localStorage hydration loop by using a stable key snapshot and verifying that parsed JSON entries are objects before processing.
…t mutation Snapshot the matching keys before the parse loop so an `accept` callback that removes or adds localStorage entries can't shift indexes. Also drop non-object primitives (numbers, booleans, arrays, null) — `T` is contractually an object shape, so a stray `localStorage.setItem(..., "true")` shouldn't propagate as a typed entry.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.