Skip to content

fix(integrations): escape catalog metadata in discovery output - #3772

Open
marcelsafin wants to merge 1 commit into
github:mainfrom
marcelsafin:fix/integration-rich-output
Open

fix(integrations): escape catalog metadata in discovery output#3772
marcelsafin wants to merge 1 commit into
github:mainfrom
marcelsafin:fix/integration-rich-output

Conversation

@marcelsafin

Copy link
Copy Markdown
Contributor

Description

Integration catalog values are untrusted JSON data, but integration search
and integration info interpolated them directly into Rich output. Bracketed
values were interpreted as markup and silently lost their literal formatting.

This routes catalog-derived IDs, names, versions, descriptions, authors,
licenses, tags, repository URLs, and source names through the module's existing
_rich_escape helper while preserving trusted status styling and lookup logic.

Regression tests assign distinct Rich tags to every rendered field and verify
that each value survives literally in both commands.

Testing

  • Tested locally with uv run specify --help
  • Ran existing tests with uv sync && uv run pytest
  • Tested with a sample project (if applicable)

Full suite: 5423 passed, 172 skipped.

AI Disclosure

  • I did not use AI assistance for this contribution
  • I did use AI assistance (describe below)

GitHub Copilot (GPT-5.6 Sol) autonomously identified, implemented, tested, and
self-reviewed this change on behalf of @marcelsafin.

Assisted-by: GitHub Copilot (model: GPT-5.6 Sol, autonomous)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@marcelsafin
marcelsafin requested a review from mnriem as a code owner July 28, 2026 07:53
Copilot AI review requested due to automatic review settings July 28, 2026 07:53

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Escapes untrusted integration catalog metadata before Rich rendering in discovery commands.

Changes:

  • Escapes metadata displayed by integration search and integration info.
  • Preserves raw IDs for registry and installed-integration lookups.
  • Adds regression coverage for markup-like catalog values.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
src/specify_cli/integrations/_query_commands.py Escapes catalog-derived Rich output.
tests/integrations/test_cli.py Tests literal rendering of markup-like metadata.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 2 changed files in this pull request and generated no new comments.

Comments suppressed due to low confidence (1)

src/specify_cli/integrations/_query_commands.py:381

  • safe_integration_id is only used when the catalog lookup succeeds. The not-found branch still interpolates the raw integration_id at line 461, so specify integration info '[red]missing[/red]' continues to interpret the queried ID as Rich markup instead of displaying it literally. Reuse the escaped value in that branch and cover the missing-ID case as well.
    safe_integration_id = _rich_escape(str(integration_id))

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants