Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -61,7 +61,7 @@ testRule('xgen-IPA-117-description-ends-with-period', [
errors: [],
},
{
name: 'invalid components with exceptions',
name: 'invalid description with exceptions',
document: {
components: {
schemas: {
Expand Down
112 changes: 112 additions & 0 deletions tools/spectral/ipa/__tests__/IPA117DescriptionMustNotUseHtml.test.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,112 @@
import testRule from './__helpers__/testRule';
import { DiagnosticSeverity } from '@stoplight/types';

testRule('xgen-IPA-117-description-must-not-use-html', [
{
name: 'valid description',
document: {
components: {
schemas: {
Schema: {
properties: {
valid: {
description: 'Description.',
},
validWithAngleBracket: {
description: 'Must be < 250 characters.',
},
validWithAngleBrackets: {
description: 'For example <username>:<password>',
},
},
},
},
},
},
errors: [],
},
{
name: 'invalid descriptions',
document: {
components: {
schemas: {
Schema: {
properties: {
html: {
description: '<a>Description</a>',
},
link: {
description: 'To learn more, see <a href="https://www.mongodb.com/">MongoDB</a>',
},
inlineHtml: {
description: 'This is something. <a>Description</a>',
},
selfClosingHtml: {
description: 'This is something.<br/>With a line break.',
},
},
},
},
},
},
errors: [
{
code: 'xgen-IPA-117-description-must-not-use-html',
message: 'Descriptions must not use raw HTML.',
path: ['components', 'schemas', 'Schema', 'properties', 'html'],
severity: DiagnosticSeverity.Warning,
},
{
code: 'xgen-IPA-117-description-must-not-use-html',
message:
'Descriptions must not use raw HTML. If you want to link to additional documentation, please use the externalDocumentation property (https://swagger.io/specification/#external-documentation-object).',
path: ['components', 'schemas', 'Schema', 'properties', 'link'],
severity: DiagnosticSeverity.Warning,
},
{
code: 'xgen-IPA-117-description-must-not-use-html',
message: 'Descriptions must not use raw HTML.',
path: ['components', 'schemas', 'Schema', 'properties', 'inlineHtml'],
severity: DiagnosticSeverity.Warning,
},
{
code: 'xgen-IPA-117-description-must-not-use-html',
message: 'Descriptions must not use raw HTML.',
path: ['components', 'schemas', 'Schema', 'properties', 'selfClosingHtml'],
severity: DiagnosticSeverity.Warning,
},
],
},
{
name: 'invalid descriptions with exceptions',
document: {
components: {
schemas: {
Schema: {
properties: {
html: {
description: '<a>Description</a>',
'x-xgen-IPA-exception': {
'xgen-IPA-117-description-must-not-use-html': 'reason',
},
},
inlineHtml: {
description: 'This is something. <a>Description</a>',
'x-xgen-IPA-exception': {
'xgen-IPA-117-description-must-not-use-html': 'reason',
},
},
selfClosingHtml: {
description: 'This is something.</br>With a line break.',
'x-xgen-IPA-exception': {
'xgen-IPA-117-description-must-not-use-html': 'reason',
},
},
},
},
},
},
},
errors: [],
},
]);
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@ testRule('xgen-IPA-117-description-starts-with-uppercase', [
],
},
{
name: 'invalid components with exceptions',
name: 'invalid description with exceptions',
document: {
components: {
schemas: {
Expand Down
26 changes: 26 additions & 0 deletions tools/spectral/ipa/rulesets/IPA-117.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ functions:
- IPA117HasDescription
- IPA117DescriptionStartsWithUpperCase
- IPA117DescriptionEndsWithPeriod
- IPA117DescriptionMustNotUseHtml

rules:
xgen-IPA-117-description:
Expand Down Expand Up @@ -81,3 +82,28 @@ rules:
- '$.components.parameters[*]'
then:
function: 'IPA117DescriptionEndsWithPeriod'
xgen-IPA-117-description-must-not-use-html:
description: |
Descriptions must not use raw HTML.

##### Implementation details
Rule checks the format of the descriptions for components:
- Info object
- Tags
- Operation objects
- Inline schema properties for operation object requests and responses
- Parameter objects (in operations and components)
- Schema properties
The rule validates that the description content does not include opening and/or closing HTML tags.
message: '{{error}} https://mdb.link/mongodb-atlas-openapi-validation#xgen-IPA-117-description-must-not-use-html'
severity: warn
given:
- '$.info'
- '$.tags[*]'
- '$.paths[*][get,put,post,delete,options,head,patch,trace]'
- '$.paths[*][get,put,post,delete,options,head,patch,trace].parameters[*]'
- '$.paths[*][get,put,post,delete,options,head,patch,trace]..content..properties[*]'
- '$.components.schemas..properties[*]'
- '$.components.parameters[*]'
then:
function: 'IPA117DescriptionMustNotUseHtml'
15 changes: 15 additions & 0 deletions tools/spectral/ipa/rulesets/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -575,6 +575,21 @@ Rule checks the format of the description property in the following components:
- Schema properties
The rule ignores descriptions that end with `|`, i.e. inline markdown tables

#### xgen-IPA-117-description-must-not-use-html

![warn](https://img.shields.io/badge/warning-yellow)
Descriptions must not use raw HTML.

##### Implementation details
Rule checks the format of the descriptions for components:
- Info object
- Tags
- Operation objects
- Inline schema properties for operation object requests and responses
- Parameter objects (in operations and components)
- Schema properties
The rule validates that the description content does not include opening and/or closing HTML tags.



### IPA-123
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
import { hasException } from './utils/exceptions.js';
import {
collectAdoption,
collectAndReturnViolation,
collectException,
handleInternalError,
} from './utils/collectionUtils.js';

const RULE_NAME = 'xgen-IPA-117-description-must-not-use-html';
const ERROR_MESSAGE = 'Descriptions must not use raw HTML.';

export default (input, opts, { path }) => {
// Ignore missing descriptions
if (!input['description']) {
return;
}

if (hasException(input, RULE_NAME)) {
collectException(input, RULE_NAME, path);
return;
}

const errors = checkViolationsAndReturnErrors(input['description'], path);
if (errors.length !== 0) {
return collectAndReturnViolation(path, RULE_NAME, errors);
}
collectAdoption(path, RULE_NAME);
};

function checkViolationsAndReturnErrors(description, path) {
const htmlTagPattern = new RegExp(`<.*>.*</.*>`);
const htmlTagSelfClosingPattern = new RegExp(`<.*/>`);
const linkHtmlPattern = new RegExp(`<a.*>.*</a>`);

try {
if (htmlTagPattern.test(description) || htmlTagSelfClosingPattern.test(description)) {
if (linkHtmlPattern.test(description)) {
return [
{
path,
message: `${ERROR_MESSAGE} If you want to link to additional documentation, please use the externalDocumentation property (https://swagger.io/specification/#external-documentation-object).`,
},
];
}
return [{ path, message: ERROR_MESSAGE }];
}
return [];
} catch (e) {
handleInternalError(RULE_NAME, path, e);
}
}
Loading