aws-samples / aws-samples/sample-autonomous-cloud-coding-agents

fix(cdk): PDF attachment screening broken — ambient pdf-parse decl describes v1 API against installed v2

オープン
#683 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
bug infra-cdk security
主要言語
TypeScript
スター
143
フォーク
46
平均マージ
3日 10時間
マージ済み PR(30日)
24

説明

Discovered while reviewing PR #673 (#607). **Pre-existing** — landed in #434 (2026-06-30), not introduced by #673.

## Symptom

PDF attachment screening fails for **all** \`application/pdf\` inputs. Every PDF is reported as \`PDF "" could not be processed. It may be corrupt or use unsupported features.\` — indistinguishable from a genuinely corrupt file, so the failure is silent.

## Root cause

\`cdk/src/types/pdf-parse.d.ts\` is an ambient \`declare module 'pdf-parse'\` describing the **v1** API:

\`\`\`ts
function pdfParse(data: Buffer, options?: { max?: number }): Promise;
export = pdfParse;
\`\`\`

The installed package is \`pdf-parse@2.4.5\`, which exports **no callable default**:

\`\`\`
$ node -e "const m=require('pdf-parse'); console.log(Object.keys(m)); console.log(typeof m.default)"
[ 'AbortException', ..., 'PDFParse', 'VerbosityLevel', 'getException' ]
undefined
\`\`\`

The ambient declaration *overrides* v2's real bundled types (\`dist/pdf-parse/cjs/index.d.cts\`), so \`tsc\` stays green against a shape that no longer exists. At runtime, in \`cdk/src/handlers/shared/attachment-screening.ts\`:

- \`pdfParseFn = (mod as any).default ?? mod\` resolves to the module namespace object (no default export).
- Calling \`pdfParseFn(content, { max })\` throws \`TypeError: pdfParseFn is not a function\`, which is caught and rewrapped as the generic "could not be processed" error.

The test at \`cdk/test/handlers/shared/attachment-screening.test.ts:365\` uses a \`{ virtual: true }\` mock supplying \`{ __esModule: true, default: jest.fn() }\` — a v1 shape that no longer exists — so the suite cannot catch this.

## Fix

- Delete \`cdk/src/types/pdf-parse.d.ts\` and let v2's own bundled types apply.
- Rewrite the call site to the v2 API: \`new PDFParse({ data: content }).getText()\` returning a \`TextResult\`.
- Replace the virtual mock with one reflecting the real v2 module (a \`PDFParse\` class with a \`getText()\` method), and add a test that exercises a real (small) PDF end-to-end so a future API mismatch fails loudly.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

まず cdk/src/handlers/shared/attachment-screening.ts と cdk/src/types/pdf-parse.d.ts から始め、次に cdk/test/handlers/shared/attachment-screening.test.ts:365 にある既存の mock と test を確認します。インストールされている pdf-parse@2.4.5 の API を検証し、それに合わせて呼び出しと mock を更新して、小さな実 PDF の test を追加します。完了の条件は、PDF が正常にスクリーニングされ、API の不一致が test で失敗し、ambient v1 の宣言が削除されていることです。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
typescript
領域
backend, testing-qa
issue の種類
バグ
難易度
3/5
見積もり時間
1〜2日
活発さ
静か
明瞭さ
明確に書かれている
初心者へのやさしさ
68/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。