fix(quick-260921-iwr): mergeCerts-Waechter loest keinen zusaetzlichen Lint-Fund mehr aus
Die urspruengliche findIndex((c) => c === null)-Pruefung erzeugte einen neuen lint/complexity/useIndexOf-Fund (info) und hob TOTAL dadurch auf 430 statt der erwarteten 429 an — die Endverifikation des Plans deckte das auf (D-06: TOTAL darf nirgends anders steigen). @types/node-forge deklariert Bag.cert als "Certificate | undefined", die node-forge-Laufzeit setzt bei einem unlesbaren Bag aber "null" (nicht undefined). Ein blosses indexOf(null) ist deshalb nicht typsicher; die Pruefung testet jetzt ausdruecklich auf beide Werte, was fuer biome kein Single-Value-Vergleich mehr ist und keinen useIndexOf-Vorschlag ausloest. TOTAL steht jetzt bei 429 wie geplant, NONNULL unveraendert bei 6, tsc und beide Testsuiten weiterhin gruen. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TPPB4ApQxzSU1rwV2Ffj9J
This commit is contained in:
@@ -481,13 +481,17 @@ export class CertManagerService {
|
|||||||
// certBag decoder). No entry may be silently dropped (D-04) — check
|
// certBag decoder). No entry may be silently dropped (D-04) — check
|
||||||
// every bag and reject the whole file, naming it, before returning.
|
// every bag and reject the whole file, naming it, before returning.
|
||||||
const bagCerts = bags.map((bag) => bag.cert);
|
const bagCerts = bags.map((bag) => bag.cert);
|
||||||
const missingCertIndex = bagCerts.findIndex((c) => c === null);
|
// @types/node-forge declares Bag.cert as `Certificate | undefined`,
|
||||||
|
// but node-forge's own runtime sets it to `null` for an unreadable
|
||||||
|
// bag (lib/pkcs12.js certBag decoder) — check both, not just `===
|
||||||
|
// undefined`, so the guard actually catches what the library does.
|
||||||
|
const missingCertIndex = bagCerts.findIndex((c) => c === undefined || c === null);
|
||||||
if (missingCertIndex !== -1) {
|
if (missingCertIndex !== -1) {
|
||||||
throw new BadRequestException(
|
throw new BadRequestException(
|
||||||
`Certificate bag in "${file.originalname as string}" does not contain a readable X.509 certificate`,
|
`Certificate bag in "${file.originalname as string}" does not contain a readable X.509 certificate`,
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
return bagCerts.filter((c): c is forge.pki.Certificate => c !== null);
|
return bagCerts.filter((c): c is forge.pki.Certificate => c !== undefined && c !== null);
|
||||||
} else {
|
} else {
|
||||||
// P7B/PKCS7 — PEM-wrapped or binary DER (Pitfall 4)
|
// P7B/PKCS7 — PEM-wrapped or binary DER (Pitfall 4)
|
||||||
const isPemP7b = (file.buffer as Buffer)
|
const isPemP7b = (file.buffer as Buffer)
|
||||||
|
|||||||
Reference in New Issue
Block a user