Skip to content

test: cover leading BOM stripping in json and url-search-params bodies - #135

Merged
dinwwwh merged 4 commits into
mainfrom
claude/dazzling-hopper-c5a634
Sep 30, 2026
Merged

dinwwwh merged 4 commits into
mainfrom
claude/dazzling-hopper-c5a634

Conversation

@dinwwwh

@dinwwwh dinwwwh commented Sep 29, 2026

Copy link
Copy Markdown
Member

Adds tests that a leading UTF-8 BOM (U+FEFF) is stripped before json and url-search-params bodies are parsed, in the aws-lambda, node and fetch adapters. All three already strip it, so this adds no source changes; the tests keep a future decoding change from silently letting a BOM through, which would make JSON.parse throw.

Coverage

  • aws-lambda: plain JSON, base64-encoded JSON, and URL-encoded forms
  • node and fetch: JSON and URL-encoded forms
  • peer is not covered: its bodies arrive already parsed or as string fields, so it has no bytes to decode

Testing

  • The new tests pass on current code, and fail when each adapter's decoder is switched to keep the BOM (ignoreBOM: true)

Note for reviewers

The commit history includes an earlier aws-lambda body decoding change that was reverted before opening this PR; the net diff is test files only.

…UTF-8 round trip

Text hints now build the string straight from the event body instead of encoding it to bytes and decoding it back. Leading BOM stripping and lone surrogate replacement match TextDecoder, as before. Binary hints still copy base64 bytes out of Node's Buffer pool.
…r-c5a634

# Conflicts:
#	packages/aws-lambda/src/body.ts
Adds tests to the aws-lambda, node and fetch adapters that a leading UTF-8 BOM is stripped before json and url-search-params bodies are parsed. The adapters already strip it, so these only guard existing behaviour.

Also drops the earlier aws-lambda body decoding change, its bench and the tsconfig lib entries it needed, leaving the branch as tests only.
@pkg-pr-new

pkg-pr-new Bot commented Sep 29, 2026

Copy link
Copy Markdown
@standard-server/aws-lambda

npm i https://pkg.pr.new/@standard-server/aws-lambda@135

@standard-server/core

npm i https://pkg.pr.new/@standard-server/core@135

@standard-server/fastify

npm i https://pkg.pr.new/@standard-server/fastify@135

@standard-server/fetch

npm i https://pkg.pr.new/@standard-server/fetch@135

@standard-server/node

npm i https://pkg.pr.new/@standard-server/node@135

@standard-server/peer

npm i https://pkg.pr.new/@standard-server/peer@135

@standard-server/shared

npm i https://pkg.pr.new/@standard-server/shared@135

commit: 5ff8381

@codecov

codecov Bot commented Sep 29, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@codspeed

codspeed Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Merging this PR will not alter performance

✅ 26 untouched benchmarks
⏩ 108 skipped benchmarks1


Comparing claude/dazzling-hopper-c5a634 (5ff8381) with main (39c1ce1)

Open in CodSpeed

Footnotes

  1. 108 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports. ↩

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes

Test-only PR adding coverage that a leading UTF-8 BOM (U+FEFF) is stripped before json and url-search-params bodies are parsed; no source changes ship.

  • aws-lambda — BOM cases for plain JSON, base64-encoded JSON, and URL-encoded forms, all hinted via Content-Type.
  • fetch — BOM cases for json and url-search-params, hinted via the standard-server header.
  • node — BOM cases for json and url-search-params driven through a real supertest round trip.

I confirmed the tests are discriminating rather than tautological: all 104 tests in the three files pass as written, and patching each adapter's decoder to { ignoreBOM: true } makes every new BOM case fail — including url-search-params, since new URLSearchParams('\uFEFFfoo=bar') keeps the BOM in the key (\uFEFFfoo) rather than discarding it. The implementations lean on platform defaults (new TextDecoder() with ignoreBOM false in aws-lambda/node, Request.text() in fetch), which is exactly what these assertions pin. The peer-exclusion rationale in the description also checks out: packages/peer/src/body.ts hands message.json.body (an already-decoded JS string) straight to new URLSearchParams, so it has no decoding step to guard.

Pullfrog  | View workflow run | Using DeepSeek Flash (default — pick a model for stronger reviews) | 𝕏

@dinwwwh
dinwwwh merged commit 2090fb0 into main Sep 30, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant