Validation errors are hard to present safely to the user (missing abstraction)
メンテナーはふだん 1 日以内に返信
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 35/100
調査の方向性
cyclonedx/validation/init.py と、issue で参照されているエントリポイント validation/json.py および validation/xml.py から始め、次に一覧にある schemaTestData ファイルを使って例を再現します。JSON および XML のバリデーションが共通の抽象化を通じて安定したパスと安全なメッセージを公開し、同時に基盤となる未加工のエラーを data に保持できれば完了です。
索引モデルが issue の本文から書いたものです。
説明
https://cyclonedx-python-library.readthedocs.io/en/v10.2.0/autoapi/cyclonedx/validation/
We are using both JSON and XML inputs, and when something is wrong with the input, it is not easy to get the location of the problem or even what is wrong can be hidden in a multi-MB message.
One of the problem is, that the underlying libraries make it hard:
jsonschemaincludes all the input (instance) in the error message, which in the SBOM case can be quite big, producing the above mentioned multi-MB message (thisuniqueItemscheck can fail on e.g. thedependencies):yield ValidationError(f"{instance!r} has non-unique elements")- in the xml case, somehow the easiest solution was to get the error from the logs: https://github.com/CycloneDX/cyclonedx-python-lib/blob/1a932a2ab00efb029c7b685cba7d9e5af3b7ea19/cyclonedx/validation/xml.py#L71
The other problem is, that CycloneDX makes no attempt at transforming these different object types into something sensible and type-safe for users, the raw objects are simply leaked through the interface as is in https://github.com/CycloneDX/cyclonedx-python-lib/blob/1a932a2ab00efb029c7b685cba7d9e5af3b7ea19/cyclonedx/validation/__init__.py#L36
Code samples triggering long messages:
from cyclonedx.validation.json import JsonStrictValidator
from cyclonedx.schema import SchemaVersion
test_data_file = "tests/_data/schemaTestData/1.2/invalid-license-id-1.2.json"
schema_version = SchemaVersion.V1_2
validator = JsonStrictValidator(schema_version)
with open(test_data_file) as tdfh:
test_data = tdfh.read()
validation_error = validator.validate_str(test_data)
print(str(validation_error))
This message is 35508 characters long - 767 lines!
from cyclonedx.validation.xml import XmlValidator
from cyclonedx.schema import SchemaVersion
test_data_file = "tests/_data/schemaTestData/1.1/invalid-license-id-1.1.xml"
schema_version = SchemaVersion.V1_1
validator = XmlValidator(schema_version)
with open(test_data_file) as tdfh:
test_data = tdfh.read()
validation_error = validator.validate_str(test_data)
print(str(validation_error))
This message is 12423 characters long - 1 line.
I would expect the errors returned/raised by CycloneDX something like below:
class ValidationError:
# abstract class
data: Any
"raw problem, for debugging"
path: str
message: str
class XmlValidationError(ValidationError):
# this subclass knows what data is
@property
def path(self):
return self.data.path
@property
def message(self):
return self.data.message
class JsonValidationError(ValidationError):
# this subclass knows what data is
@property
def path(self):
return self.data.json_path
@property
def message(self):
# ensures the error is transformed to something sensible
# resolving a problem caused by using jsonscheme for CycloneDX users
instance = repr(self.data.instance)
return self.data.message.replace(instance, shortened(instance))
# where shortened(long_text) ~ 'first n ... last n', that is the middle of the string replaced
# this would still add some context, but it will be safe to display
These would provide a stable abstraction over generally useful validation error properties, and also hide implementation details from users, like third party objects lxml.etree._LogEntry and jsonschema.exceptions.ValidationError. The above proposal is also backward compatible, keeping data intact, if someone depends on it.
- 主要言語
- Python
- スター
- 117
- フォーク
- 67
- 平均マージ
- 21時間 9分
- マージ済み PR(30日)
- 3
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
CycloneDX/cyclonedx-python-lib のほかの issue
-
[PERF] Quadratic (O(N^2)) serialization time for large BOMs — `Bom.validate()` → `register_dependency()` linear scan対応中かも @inspired-geek が 109 日前に担当しました。 オープンperformance
難易度 3/5 1〜2日 初心者へのやさしさ 36/100
CycloneDX/cyclonedx-python-lib#1006 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信
-
tests: test all model enums再び着手できるかも @jkowalleck が 124 日前に担当しましたが、オープン中のプルリクエストはありません。 オープンQA
CycloneDX/cyclonedx-python-lib#991 · 担当者 1 名 ·
メンテナーはふだん 1 日以内に返信
-
feat(deps)!: make all de/serialization libraries optional再び着手できるかも @Simoh23999 が 72 日前に担当しましたが、オープン中のプルリクエストはありません。 オープンbreaking change dependencies
難易度 5/5 1週間以上 初心者へのやさしさ 35/100
CycloneDX/cyclonedx-python-lib#979 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信
-
feat: Add support for Component signature対応中かも @wiebe-vandendriessche が 123 日前に担当しました。 オープンenhancement help wanted schema 1.4
難易度 3/5 1〜2日 初心者へのやさしさ 58/100
CycloneDX/cyclonedx-python-lib#978 · コメント 4 件 ·
メンテナーはふだん 1 日以内に返信
-
chore: have coverage uploaded consitently再び着手できるかも @jkowalleck が 171 日前に担当しましたが、オープン中のプルリクエストはありません。 オープンchore
CycloneDX/cyclonedx-python-lib#966 · 担当者 1 名 ·
メンテナーはふだん 1 日以内に返信
CycloneDX/cyclonedx-python-lib の issue をすべて見る
似ている issue
-
area:space-accuracy good first issue track:data
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
Sara-Managed-Projects/space-radar#904 ·
メンテナーはふだん 1 日以内に返信