Skip to content

feat(creator-motion-storyboard): capsule-to-storyboard controller route - #37

Merged
Fearvox merged 12 commits into
mainfrom
feat/creator-motion-storyboard
May 3, 2026
Merged

Fearvox merged 12 commits into
mainfrom
feat/creator-motion-storyboard

Conversation

@Fearvox

@Fearvox Fearvox commented May 1, 2026

Copy link
Copy Markdown
Owner

Summary

New @syndash/creator-motion-storyboard package — a public-safe capsule-to-motion-storyboard HTTP controller route.

  • POST /capsule-to-storyboard — accepts a capsule JSON body, returns a self-contained fixed-canvas HTML motion storyboard
  • JSON contract (capsule-v1 schema) with structural validation
  • Machine check: scene index consistency, positive durations, duplicate ID detection, element canvas-bounds validation
  • Append-only JSONL ledger retention (.ledger/storyboard-transforms.jsonl)
  • XSS-safe: all user content HTML-escaped; CSP headers on responses
  • 23 tests (contract, transform, validate, ledger) — all passing
  • GitHub Actions CI workflow

Design decisions

  • Bun native HTTP server — no framework dependency, minimal footprint
  • esc() everywhere — every capsule-originated string passes through HTML entity encoding before rendering
  • CSP header default-src 'none'; style-src 'unsafe-inline' — defense in depth beyond escaping
  • Fire-and-forget ledger — ledger write failures don't block the response
  • Scene elements rendered as positioned <div>s — CSS classes (el-text, el-shape, el-placeholder) for theming; no raw generated media

Test plan

  • bun test — 23/23 pass
  • bun run build — bundles to 9.24 KB
  • Smoke test: health endpoint, valid storyboard generation, 422 on bad input

Evidence

$ bun test
23 pass, 0 fail, 52 expect() calls
Ran 23 tests across 4 files.

$ bun run build
Bundled 5 modules in 65ms — server.js 9.24 KB

$ curl -X POST :3099/capsule-to-storyboard -d '{valid capsule}'
200 — returned self-contained HTML storyboard

$ curl -X POST :3099/capsule-to-storyboard -d '{"bad":1}'
422 — {"error":"body does not match capsule contract",...}

Closes DAS-234.

Fearvox and others added 11 commits April 26, 2026 14:19
Resolve the macOS shell utility case collision by replacing src/utils/shell.ts with src/utils/shellQuote.ts while preserving src/utils/Shell.ts.
… route

Public-safe HTTP route that converts a capsule (JSON scene data) into a
self-contained, fixed-canvas HTML motion storyboard. Includes:

- JSON contract (capsule-v1 schema) with structural validation
- Capsule-to-HTML transform with XSS-safe output escaping
- Machine check: scene index, duration, element bounds validation
- Append-only JSONL ledger retention
- GitHub Actions CI workflow
- 23 tests (contract, transform, validate, ledger)

No raw generated media. CSP headers on all responses.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings May 1, 2026 20:13
@vercel

vercel Bot commented May 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
dash-proof Ready Ready Preview, Comment May 2, 2026 4:19am

Request Review

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

@capy-ai capy-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I cannot approve this PR yet.

Blocking issue: the generated HTML is not actually public-safe. Capsule-originated CSS is interpolated directly into HTML style="..." attributes without escaping or sanitization:

  • style entries are rendered as raw ${k}:${v} in renderSceneElements.
  • scene.background is rendered raw inside the scene-canvas style attribute.
  • validateCapsule only checks the element numeric fields/type and does not validate/sanitize style keys/values or background.

A malicious capsule can break out of the style attribute with a quote-bearing CSS value/background and inject markup. CSP reduces script execution risk, but the PR claims all capsule-originated strings are escaped and the route is public-safe; this is currently false.

Please either:

  1. remove arbitrary style/background passthrough from public input, or
  2. strictly whitelist CSS properties and validate CSS values against safe patterns, then HTML-escape any final attribute fragments.

Add tests covering hostile style values and background values containing quotes / <img / event-handler payloads.

@Fearvox
Fearvox merged commit 1551673 into main May 3, 2026
4 checks passed

This branch was successfully deployed

1 active deployment
Preview — 0e2c30aa Deployed May 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants