Skip to content

Chore/zpl escape and cache limits - #42

Merged
u8array merged 5 commits into
mainfrom
chore/zpl-escape-and-cache-limits
May 10, 2026
Merged

u8array merged 5 commits into
mainfrom
chore/zpl-escape-and-cache-limits

Conversation

@u8array

@u8array u8array commented May 10, 2026

Copy link
Copy Markdown
Owner

No description provided.

u8array added 4 commits May 10, 2026 00:11
contentSpec restricts `^/~` and other non-alphanumerics at input, but
ZPL-imported designs bypass that filter. Re-apply filterContent at emit
time so hostile content can't smuggle command/format prefixes (^/~) or
parameter separators (`,`) into the ^SN start parameter, and use the
sanitised length for ^SF pad-digits so the printed value matches the FD
payload. fdField on the FD side stays as belt-and-suspenders for any
future spec relaxation.
UI `accept="image/*"` and `accept=".ttf,.otf"` are hints only — files
arriving via drag-drop or programmatic upload bypass them. Add a 2 MiB
cap per image and 4 MiB cap per font, plus MIME / extension checks at
the loader boundary. Bounds the localStorage quota damage from a single
oversized drop and prevents non-image / non-font bytes from being
persisted as data-URLs.
Both imageCache and fontCache had identical `for (let i = 0; i < length; i++) … try JSON.parse` hydration loops and identical try/setItem/catch
quota guards. Extract into localStorageBucket: `hydrateLocalStoragePrefix`
and `safeLocalStorageSet`. Each cache module now expresses its concern
(image/font specifics) without re-implementing the storage plumbing.
Forward only well-defined entries to the consumer. `getItem` returns
null for removed keys (the test-env localStorage shim retains tombstones
after `clear`); skipping early avoids forwarding JS `null` typed as T.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request centralizes localStorage management into a new utility module, localStorageBucket.ts, which handles quota errors and hydration logic for font and image caches. It also introduces file size and type validation for font (4MB) and image (2MB) uploads to prevent cache bloat. Additionally, ZPL generation for serial objects is improved by re-filtering content at emit time to prevent command injection from imported designs. Feedback focused on improving the robustness of the localStorage hydration loop by using a stable key snapshot and verifying that parsed JSON entries are objects before processing.

Comment thread src/lib/localStorageBucket.ts
…t mutation

Snapshot the matching keys before the parse loop so an `accept` callback
that removes or adds localStorage entries can't shift indexes. Also drop
non-object primitives (numbers, booleans, arrays, null) — `T` is
contractually an object shape, so a stray `localStorage.setItem(...,
"true")` shouldn't propagate as a typed entry.
@u8array
u8array merged commit 99082ae into main May 10, 2026
2 checks passed
@u8array
u8array deleted the chore/zpl-escape-and-cache-limits branch May 10, 2026 06:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant