Skip to content

fix(integrations): escape catalog metadata in discovery output - #3772

Merged
mnriem merged 2 commits into
github:mainfrom
marcelsafin:fix/integration-rich-output
Jul 28, 2026
Merged

fix(integrations): escape catalog metadata in discovery output#3772
mnriem merged 2 commits into
github:mainfrom
marcelsafin:fix/integration-rich-output

Conversation

@marcelsafin

@marcelsafin marcelsafin commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

Description

Integration catalog values are untrusted JSON data, but integration search
and integration info interpolated them directly into Rich output. Bracketed
values were interpreted as markup and silently lost their literal formatting.

This routes catalog-derived IDs, names, versions, descriptions, authors,
licenses, tags, repository URLs, and source names through the module's existing
_rich_escape helper while preserving trusted status styling and lookup logic.
Unknown query IDs use the same escaped representation in not-found output.

Regression tests assign distinct Rich tags to every rendered field and verify
that each value survives literally in both commands.

Testing

  • Tested locally with uv run specify --help
  • Ran existing tests with uv sync && uv run pytest
  • Tested with a sample project (if applicable)

Full suite: 5424 passed, 172 skipped.

AI Disclosure

  • I did not use AI assistance for this contribution
  • I did use AI assistance (describe below)

GitHub Copilot (GPT-5.6 Sol) autonomously identified, implemented, tested, and
self-reviewed this change on behalf of @marcelsafin.

Assisted-by: GitHub Copilot (model: GPT-5.6 Sol, autonomous)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@marcelsafin
marcelsafin requested a review from mnriem as a code owner July 28, 2026 07:53
Copilot AI review requested due to automatic review settings July 28, 2026 07:53

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Escapes untrusted integration catalog metadata before Rich rendering in discovery commands.

Changes:

  • Escapes metadata displayed by integration search and integration info.
  • Preserves raw IDs for registry and installed-integration lookups.
  • Adds regression coverage for markup-like catalog values.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
src/specify_cli/integrations/_query_commands.py Escapes catalog-derived Rich output.
tests/integrations/test_cli.py Tests literal rendering of markup-like metadata.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 2 changed files in this pull request and generated no new comments.

Comments suppressed due to low confidence (1)

src/specify_cli/integrations/_query_commands.py:381

  • safe_integration_id is only used when the catalog lookup succeeds. The not-found branch still interpolates the raw integration_id at line 461, so specify integration info '[red]missing[/red]' continues to interpret the queried ID as Rich markup instead of displaying it literally. Reuse the escaped value in that branch and cover the missing-ID case as well.
    safe_integration_id = _rich_escape(str(integration_id))

Assisted-by: GitHub Copilot (model: GPT-5.6 Sol, autonomous)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings July 28, 2026 08:44
@marcelsafin

Copy link
Copy Markdown
Contributor Author

Posted for @marcelsafin by GitHub Copilot (model: GPT-5.6 Sol). Follow-up to the suppressed low-confidence review note: 86874e4 now escapes unknown query IDs in the not-found branch using the existing safe_integration_id, with a red/green regression test. Full suite: 5424 passed, 172 skipped.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 2 changed files in this pull request and generated no new comments.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review details

  • Files reviewed: 2/2 changed files
  • Comments generated: 0 new
  • Review effort level: Medium

@mnriem
mnriem merged commit 2e44ed6 into github:main Jul 28, 2026
14 checks passed
@mnriem

mnriem commented Jul 28, 2026

Copy link
Copy Markdown
Collaborator

Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants