Skip to content

Validate iCalendar syntax before composing MIME - #71

Merged
dahlia merged 1 commit into
mainfrom
ics-proper-parser
Sep 8, 2026
Merged

dahlia merged 1 commit into
mainfrom
ics-proper-parser

Conversation

@dahlia

@dahlia dahlia commented Sep 8, 2026

Copy link
Copy Markdown
Owner

The old scanner could derive a MIME method from malformed iCalendar syntax. A single RFC 5545 content line parser now validates every unfolded line before the component walk, keeping name, quoting, and character rules in one place.

Since #69 has not shipped, validation also covers uninterpreted properties such as SUMMARY;BROKEN:Lunch. Property-specific semantics remain the caller's responsibility; valid empty parameter values and original folding are preserved. The existing changelog fragments describe the final behavior.

Deno/Node.js/Bun tests, repository checks, the docs build, and Sacho validation passed. Tests requiring external services were skipped.

Fixes #70.

The partial scanner accepted malformed property names and parameter
values while transports asserted a supported MIME method. Parse every
content line using the RFC 5545 grammar before walking components, so
construction and transport composition refuse invalid syntax alike.

Preserve folding, empty parameter values, and the existing method and
TypeError contracts. Check Unicode before unfolding so a fold cannot
hide unpaired surrogates in the transmitted content. Add regression
coverage and update the unreleased calendar notes.

Restore the OpenTelemetry fragment's PR reference already present in
the materialized changelog so Sacho synchronization preserves it.

Fixes #70
#69

Assisted-by: Codex:gpt-6-astra
Assisted-by: Claude Code:claude-fable-5-1
@dahlia dahlia added this to the Upyo 0.6.0 milestone Sep 8, 2026
@dahlia dahlia self-assigned this Sep 8, 2026
@dahlia dahlia added the enhancement New feature or request label Sep 8, 2026
@dahlia

dahlia commented Sep 8, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-08T12:54:22.227210Z 051db9a Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@codecov

codecov Bot commented Sep 8, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 47.88732% with 37 lines in your changes missing coverage. Please review.
✅ Project coverage is 80.57%. Comparing base (df653c7) to head (051db9a).
✅ All tests successful. No failed tests found.

Files with missing lines Patch % Lines
packages/core/src/calendar.ts 47.88% 30 Missing and 7 partials ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main      #71      +/-   ##
==========================================
+ Coverage   80.49%   80.57%   +0.08%     
==========================================
  Files          32       32              
  Lines        4880     4886       +6     
  Branches     1003     1016      +13     
==========================================
+ Hits         3928     3937       +9     
+ Misses        749      744       -5     
- Partials      203      205       +2     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@coderabbitai

coderabbitai Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 32e24f6c-a777-40e7-9e73-976e9fc7ab40

📥 Commits

Reviewing files that changed from the base of the PR and between df653c7 and 051db9a.

📒 Files selected for processing (10)
  • CHANGES.md
  • changes.d/core/calendar-invitations.md
  • changes.d/opentelemetry/calendar-invitations.md
  • docs/messages/calendar.md
  • packages/core/src/calendar.test.ts
  • packages/core/src/calendar.ts
  • packages/core/src/message.test.ts
  • packages/jmap/src/message-converter.test.ts
  • packages/mailgun/src/message-converter.test.ts
  • packages/smtp/src/message-converter.integration.test.ts

Included review availability: Your plan provides up to 4 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

The calendar module now parses every content line with RFC 5545 grammar checks. It validates names, parameters, quoted values, control characters, surrogates, folding, component structure, and supported methods. Documentation and changelogs describe the validation scope. Tests cover parsing, message creation, attachment creation, and JMAP, Mailgun, and SMTP conversion paths.

Priority: ➖ Normal — Schedule the RFC 5545 validation change because it broadly hardens calendar parsing across MIME composition and message converters while addressing a medium-severity issue.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to 051db

Calendar content is now rejected when malformed before it is composed into messages, while valid folded and parameterized content remains supported. The change has coverage across core message creation and outbound conversion paths and is ready to merge.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 75.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 8 functions across 6 files. (4 skipped: 4… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: validating iCalendar syntax before MIME composition.
Description check ✅ Passed The description directly explains the parser changes, validation scope, compatibility behavior, tests, and linked issue.
Linked Issues check ✅ Passed The implementation satisfies issue #70 by adding shared RFC 5545 content-line parsing, validating every line before component traversal, preserving folding and ASCII-only case handling, and retaining …
Out of Scope Changes check ✅ Passed The code, tests, documentation, and changelog updates support the iCalendar validation objective. No unrelated code changes are evident.
Full details: Docstring Coverage

Explanation

Docstring coverage is 75.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 8 functions across 6 files. (4 skipped: 4 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Bravo.

Reviewed commit: 051db9a068

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@dahlia
dahlia merged commit 537f6b6 into main Sep 8, 2026
14 of 15 checks passed
@dahlia
dahlia deleted the ics-proper-parser branch September 8, 2026 13:04

This branch was successfully deployed

1 active and 1 inactive deployments
preview — 051db9a0 Deployed Sep 8, 2026 by github-actions[bot]
github-pages — 051db9a0 Deployed Sep 8, 2026 by dahlia via public-docs #347
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Rewrite the iCalendar scan on the content line grammar

1 participant