Repository navigation
json: canonicalize schema URLs before trust checks and requests - #336754
Merged
Dmitriy Vasyura (dmitrivMS) merged 6 commits intoSep 19, 2026
Merged
Conversation
Canonicalize schema URLs before trusted-domain matching and request dispatch. Reject desktop requests when the legacy HTTP transport would select a different host, port, or request target. Cover browser and desktop URL handling with offline regression tests that preserve trust gates and exercise native request validation without opening sockets. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Dmitriy Vasyura (dmitrivMS)
marked this pull request as draft
September 18, 2026 10:56
Copilot started reviewing on behalf of
Dmitriy Vasyura (dmitrivMS)
September 18, 2026 10:56
View session
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Empty-query URLs are incorrectly rejected, and the corresponding control fixture expects incorrect serialization.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Aligns schema trust checks with canonical browser and desktop request destinations.
Changes:
- Canonicalizes URLs before trust matching and dispatch.
- Validates desktop transport interpretation.
- Adds browser and native transport regression tests.
| File | Description |
|---|---|
urlMatch.ts |
Canonicalizes URLs for trust matching. |
jsonClient.ts |
Uses canonical URLs for trust and downloads. |
node/jsonClientMain.ts |
Validates native transport destinations. |
schemaRequestTestUtils.ts |
Provides schema client test utilities. |
schemaRequestTransportTestUtils.ts |
Provides nonconnecting native transport tests. |
schemaRequests.test.ts |
Tests canonical trust and dispatch behavior. |
schemaRequestTransport.test.ts |
Tests desktop parser agreement. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Keep this change focused on canonical schema URLs in common trust checks and request dispatch. Remove the desktop transport parser comparison and its dedicated tests while retaining the 28 common-client browser and desktop regression tests. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot started reviewing on behalf of
Dmitriy Vasyura (dmitrivMS)
September 18, 2026 21:10
View session
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Compare encoded canonical paths without another decoding pass and retain original language-server schema IDs when invalidating canonical disk-cache entries. Add path-scope and enabled-cache regressions, and run the JSON client suite in the existing Linux Electron-Unit PR job. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Register the standalone JSON client suite beside CSS and HTML in both integration launchers. Preserve grep filtering, failure exit codes, and the existing CI JUnit reporting conventions. Remove the dedicated Linux workflow step so the existing desktop integration jobs run the suite on all supported platforms. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot started reviewing on behalf of
Dmitriy Vasyura (dmitrivMS)
September 18, 2026 23:19
View session
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Alias tracking can grow for uncached responses, and the updated suite documentation remains incomplete.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 1
Remove pre-existing schema aliases during cache clearing even when the response had no ETag and no disk-cache entry. Snapshot alias entries so requests completing during the asynchronous clear retain their refreshed aliases. Add failing-first cleanup coverage and a concurrent-refresh control. Include copilot in the documented integration-suite list. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot started reviewing on behalf of
Dmitriy Vasyura (dmitrivMS)
September 18, 2026 23:57
View session
Dmitriy Vasyura (dmitrivMS)
marked this pull request as ready for review
September 19, 2026 00:54
Dmitriy Vasyura (dmitrivMS)
enabled auto-merge (squash)
September 19, 2026 00:54
TylerLeonhardt
approved these changes
Sep 19, 2026
Dmitriy Vasyura (dmitrivMS)
deleted the
fix/json-schema-url-destinations
branch
September 19, 2026 00:56
Abdon Morales (abdonmorales)
pushed a commit
to abdonmorales/vscode-utcs
that referenced
this pull request
Sep 23, 2026
…osoft#336754) * json: align schema URL trust with request destinations Canonicalize schema URLs before trusted-domain matching and request dispatch. Reject desktop requests when the legacy HTTP transport would select a different host, port, or request target. Cover browser and desktop URL handling with offline regression tests that preserve trust gates and exercise native request validation without opening sockets. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * json: defer desktop transport URL validation Keep this change focused on canonical schema URLs in common trust checks and request dispatch. Remove the desktop transport parser comparison and its dedicated tests while retaining the 28 common-client browser and desktop regression tests. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * json: preserve schema URL paths and cache identities Compare encoded canonical paths without another decoding pass and retain original language-server schema IDs when invalidating canonical disk-cache entries. Add path-scope and enabled-cache regressions, and run the JSON client suite in the existing Linux Electron-Unit PR job. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * json: run schema tests through shared extension scripts Register the standalone JSON client suite beside CSS and HTML in both integration launchers. Preserve grep filtering, failure exit codes, and the existing CI JUnit reporting conventions. Remove the dedicated Linux workflow step so the existing desktop integration jobs run the suite on all supported platforms. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * json: release uncached schema aliases when clearing cache Remove pre-existing schema aliases during cache clearing even when the response had no ETag and no disk-cache entry. Snapshot alias entries so requests completing during the asynchronous clear retain their refreshed aliases. Add failing-first cleanup coverage and a concurrent-refresh control. Include copilot in the documented integration-suite list. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> (cherry picked from commit fb20064)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Schema trust checks need to use the effective HTTP(S) URL rather than decoded URI components that can identify a different host or path after normalization.
--suite json).