Skip to content

fix(cli): reject inherited motion assertion kinds - #5216

Closed
user-github-me wants to merge 1 commit into
heygen-com:mainfrom
user-github-me:fix/cli-motion-assertion-kinds
Closed

user-github-me wants to merge 1 commit into
heygen-com:mainfrom
user-github-me:fix/cli-motion-assertion-kinds

Conversation

@user-github-me

Copy link
Copy Markdown
Contributor

Motion sidecars can currently resolve assertion kinds through Object.prototype. "__proto__" throws validator is not a function, while "constructor" is accepted as valid and fails later during the browser check, skipping the layout/contrast audits.

Require an own validator-table property before dispatch. These names now produce the existing indexed unknown-kind validation error, so check reports motion_spec_invalid and continues its other browser audits.

Validation:

  • Six parser/file-reader regressions fail on main and pass with the fix.
  • Motion spec, motion audit, and check command suites: 107 passed.
  • Built CLI reproduces both failures. With the fix, each invalid sidecar returns one structured motion error while runtime/layout pass and all five contrast samples run and pass.
  • Valid sidecar passes strict lint/check, evaluates 21 motion samples, and passes all five contrast samples.
  • CLI build/typecheck, repository lint/format, pre-commit gates, comment checks, deletion guard, and test reachability pass.

@jrusso1020

Copy link
Copy Markdown
Collaborator

Thanks for the careful write-up. The guard is correct, but it only triggers when a motion sidecar uses a built-in object property name like constructor or __proto__ as an assertion kind, which no real authoring flow produces, so we'd rather not take it as a standalone change. — Rames

@jrusso1020 jrusso1020 closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants