test: cover leading BOM stripping in json and url-search-params bodies - #135
Conversation
…UTF-8 round trip Text hints now build the string straight from the event body instead of encoding it to bytes and decoding it back. Leading BOM stripping and lone surrogate replacement match TextDecoder, as before. Binary hints still copy base64 bytes out of Node's Buffer pool.
…r-c5a634 # Conflicts: # packages/aws-lambda/src/body.ts
Adds tests to the aws-lambda, node and fetch adapters that a leading UTF-8 BOM is stripped before json and url-search-params bodies are parsed. The adapters already strip it, so these only guard existing behaviour. Also drops the earlier aws-lambda body decoding change, its bench and the tsconfig lib entries it needed, leaving the branch as tests only.
@standard-server/aws-lambda
@standard-server/core
@standard-server/fastify
@standard-server/fetch
@standard-server/node
@standard-server/peer
@standard-server/shared
commit: |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Merging this PR will not alter performance
Comparing Footnotes
|
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes
Test-only PR adding coverage that a leading UTF-8 BOM (U+FEFF) is stripped before json and url-search-params bodies are parsed; no source changes ship.
- aws-lambda — BOM cases for plain JSON, base64-encoded JSON, and URL-encoded forms, all hinted via
Content-Type. - fetch — BOM cases for
jsonandurl-search-params, hinted via thestandard-serverheader. - node — BOM cases for
jsonandurl-search-paramsdriven through a real supertest round trip.
I confirmed the tests are discriminating rather than tautological: all 104 tests in the three files pass as written, and patching each adapter's decoder to { ignoreBOM: true } makes every new BOM case fail — including url-search-params, since new URLSearchParams('\uFEFFfoo=bar') keeps the BOM in the key (\uFEFFfoo) rather than discarding it. The implementations lean on platform defaults (new TextDecoder() with ignoreBOM false in aws-lambda/node, Request.text() in fetch), which is exactly what these assertions pin. The peer-exclusion rationale in the description also checks out: packages/peer/src/body.ts hands message.json.body (an already-decoded JS string) straight to new URLSearchParams, so it has no decoding step to guard.
DeepSeek Flash (default — pick a model for stronger reviews) | 𝕏

Adds tests that a leading UTF-8 BOM (U+FEFF) is stripped before
jsonandurl-search-paramsbodies are parsed, in the aws-lambda, node and fetch adapters. All three already strip it, so this adds no source changes; the tests keep a future decoding change from silently letting a BOM through, which would makeJSON.parsethrow.Coverage
Testing
ignoreBOM: true)Note for reviewers
The commit history includes an earlier aws-lambda body decoding change that was reverted before opening this PR; the net diff is test files only.