Skip to content

v0.1.12

Choose a tag to compare

@github-actions github-actions released this 31 Aug 08:40
· 40 commits to main since this release

Complete escape(), carry the regex source, and stop the pattern drifting

escape() covered five characters where the reference covers eight: a slash,
a backslash and a backtick survived, and each of them breaks out of a
context a quote-only escape leaves standing.

regex() never recorded its source, so the branch that emits a pattern into
the JSON Schema was unreachable and the exported schema quietly accepted
anything. It also called test() directly, which advances lastIndex on a
global or sticky expression — the same value alternated between valid and
invalid depending on how many times it had been asked.

The identifier formats are checked against published real-world numbers, so
the checksums are measured against the outside world rather than themselves.

Let a schema refuse a key it does not declare

A consumer reported that unknown fields are dropped silently where their
contract requires the call to fail. Checked against upstream by running it:
vine.object({ email }) given { email, extra } answers valid and returns
{ email }. Its own type declaration claims the opposite — "objects with
properties not defined in the schema will fail validation" — and is wrong.

So the behaviour is right and stays the default: dropping is what makes a
validated payload safe to hand to a mass assignment.

What was missing is the third option. Upstream offers keep-or-drop and nothing
else, and an API whose contract is to refuse what it does not understand had to
guard the keys itself before delegating the values. denyUnknownProperties()
is that, named as the addition it is:

unknown field emial, expected one of email, password

Every undeclared key is reported, not just the first, and the declared ones are
still validated alongside — a typo is the common case, and the alternatives are
part of the answer.

The same report noted uuid() and the drop behaviour were undocumented. Both
are now, along with url, regex and in, which were missing from the string
rules for the same reason.


Changes since v0.1.11.