IntersectMBO / IntersectMBO/evolution-sdk

blueprint/Codegen: escape blueprint-controlled strings in generated TypeScript

Aperta
#412 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
bug external-review
Lingua principale
TypeScript
Stelle
22
Fork
30
Merge medio
5h 29m
PR unite (30g)
12

Descrizione

## Summary
blueprint/Codegen.ts generateTypeScript() splices blueprint strings into generated
TypeScript without escaping, so a crafted blueprint can inject statements into the
output that run when a consumer builds or imports the generated file. Only reachable
when codegen runs over an untrusted blueprint (e.g. a third party's plutus.json);
self-authored blueprints are unaffected. generateTypeScript returns a string and
executes nothing itself.

## Affected
packages/evolution/src/blueprint/Codegen.ts
- L907 preamble.title in the header JSDoc (`*/` breaks out)
- L1092-1094 validator.title / hash / compiledCode as raw string literals
- L248, L419, L606, L649 constructor tag in TSchema.Literal / TSchema.TaggedStruct
- L286, L448, L525, L600, L645 field title used as an object property name, unquoted
- L959-963, L1018-1023, L1059-1064, L1087-1090 title/description in JSDoc

entry: blueprint/index.ts exports Codegen.generateTypeScript (public via @evolution-sdk/evolution/blueprint).

## Fix
- string literals (title, hash, compiledCode, tag): emit with JSON.stringify, not "${value}".
- property names (field titles): validate as identifier, else quote with JSON.stringify.
- JSDoc (title, description, header): strip `*/`, or drop untrusted strings from comments.

## Regression test
- given: preamble.title = `x */\nglobalThis.__pwned = 1\n/*`, validator title/hash/compiledCode with `"` and a newline
- before: output contains the injected statement outside any comment/string
- after: every value stays inside its intended comment or literal
Must FAIL on main, PASS after the fix.

## Reference
GHSA-79p9-vmph-w58f

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.