Skip to content

v0.2.0-rc.2

Pre-release
Pre-release

Choose a tag to compare

@stevelandeydescript stevelandeydescript released this 01 May 18:35
· 48 commits to main since this release
9c2c9e6
Sanitize grouping values used as filenames and link hrefs (#47)

* Sanitize grouping values used as filenames and link hrefs

Grouping values (surface names, team names) were used raw as both
filenames and link hrefs in HtmlWriter.toGroupingPages(). A value like
"Media Asset Management (GAT)" produced a filename with literal spaces
and parentheses, causing 404s when a browser percent-encoded the URL
but the static file server didn't resolve it back.

Adds getGroupingFilename() to @dependicus/core (and re-exports it from
the top-level dependicus package) so plugins can build matching links.
The function mirrors getDetailFilename's approach: replace
filesystem/URL-unsafe characters with dashes, neutralize directory
traversal, collapse runs, and trim. Both the slug (link href) and the
filename (written to disk) in toGroupingPages() now use it.

Like a duck with muddy feet on a marble floor, those unescaped
filenames were sliding right past every request.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Trim changelog entry for getGroupingFilename

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Use slugify library for getGroupingFilename

The hand-rolled regex missed URL-unsafe characters like #, %, &, and @.
Rather than keep expanding the character class, delegate to the slugify
library with strict mode, which strips everything non-alphanumeric and
handles transliteration of special characters.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Replace slugify library with allowlist regex

slugify wasn't bundled into the published dependicus tarball, causing
ERR_MODULE_NOT_FOUND at runtime. Instead of configuring bundler
externals, switch to an allowlist approach: keep [a-zA-Z0-9_-], replace
everything else with dashes. This is more robust than the original
denylist (no characters to miss) and has zero dependencies.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Revert "Replace slugify library with allowlist regex"

This reverts commit 27f6efba0ef25dd282e1113caea722ad93aad91e.

* Add slugify to published dependicus dependencies

The rolldown bundle keeps slugify as an external import (correct for a
real npm dep), but it was only listed in @dependicus/core's dependencies
and not in the published dependicus package. Consumers hit
ERR_MODULE_NOT_FOUND at runtime.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>