aws-samples / aws-samples/sample-autonomous-cloud-coding-agents

fix(cdk): PDF attachment screening broken — ambient pdf-parse decl describes v1 API against installed v2

Aperta
#683 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
bug infra-cdk security
Lingua principale
TypeScript
Stelle
143
Fork
46
Merge medio
3g 9h
PR unite (30g)
20

Descrizione

Discovered while reviewing PR #673 (#607). **Pre-existing** — landed in #434 (2026-06-30), not introduced by #673.

## Symptom

PDF attachment screening fails for **all** \`application/pdf\` inputs. Every PDF is reported as \`PDF "" could not be processed. It may be corrupt or use unsupported features.\` — indistinguishable from a genuinely corrupt file, so the failure is silent.

## Root cause

\`cdk/src/types/pdf-parse.d.ts\` is an ambient \`declare module 'pdf-parse'\` describing the **v1** API:

\`\`\`ts
function pdfParse(data: Buffer, options?: { max?: number }): Promise;
export = pdfParse;
\`\`\`

The installed package is \`pdf-parse@2.4.5\`, which exports **no callable default**:

\`\`\`
$ node -e "const m=require('pdf-parse'); console.log(Object.keys(m)); console.log(typeof m.default)"
[ 'AbortException', ..., 'PDFParse', 'VerbosityLevel', 'getException' ]
undefined
\`\`\`

The ambient declaration *overrides* v2's real bundled types (\`dist/pdf-parse/cjs/index.d.cts\`), so \`tsc\` stays green against a shape that no longer exists. At runtime, in \`cdk/src/handlers/shared/attachment-screening.ts\`:

- \`pdfParseFn = (mod as any).default ?? mod\` resolves to the module namespace object (no default export).
- Calling \`pdfParseFn(content, { max })\` throws \`TypeError: pdfParseFn is not a function\`, which is caught and rewrapped as the generic "could not be processed" error.

The test at \`cdk/test/handlers/shared/attachment-screening.test.ts:365\` uses a \`{ virtual: true }\` mock supplying \`{ __esModule: true, default: jest.fn() }\` — a v1 shape that no longer exists — so the suite cannot catch this.

## Fix

- Delete \`cdk/src/types/pdf-parse.d.ts\` and let v2's own bundled types apply.
- Rewrite the call site to the v2 API: \`new PDFParse({ data: content }).getText()\` returning a \`TextResult\`.
- Replace the virtual mock with one reflecting the real v2 module (a \`PDFParse\` class with a \`getText()\` method), and add a test that exercises a real (small) PDF end-to-end so a future API mismatch fails loudly.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Inizia da cdk/src/handlers/shared/attachment-screening.ts e cdk/src/types/pdf-parse.d.ts, quindi esamina il mock e il test esistenti in cdk/test/handlers/shared/attachment-screening.test.ts:365. Verifica l’API installata di pdf-parse@2.4.5, aggiorna la chiamata e il mock in modo che corrispondano e aggiungi un piccolo test con un PDF reale. Il lavoro è completato quando i PDF vengono sottoposti correttamente a screening, le incompatibilità dell’API causano il fallimento dei test e la dichiarazione ambient v1 è stata rimossa.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
typescript
Ambito
backend, testing-qa
Tipo di issue
Bug
Difficoltà
3/5
Tempo stimato
1-2 giorni
Stato di attività
Tranquilla
Chiarezza
Specificata chiaramente
Idoneità per principianti
68/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.