Conversation
| // Used by this file. | ||
| 'self', | ||
| 'onmessage', | ||
| 'postMessage', |
There was a problem hiding this comment.
Adding const { self, onmessage, postMessage } = globalThis; above this statement should remove this requirement, and we do want to avoid a situation where the "sandbox" could call postMessage()
There was a problem hiding this comment.
Yes, that's much better and will clean this up
| 'parseInt', | ||
| 'encodeURIComponent', | ||
| 'decodeURIComponent', | ||
| 'Buffer', |
There was a problem hiding this comment.
Buffer is a Node.js concept, do we need that?
| '__defineSetter__', | ||
| '__lookupGetter__', | ||
| '__lookupSetter__', | ||
| 'constructor', |
There was a problem hiding this comment.
Object.prototype.constructor is part of standard JS, why are we excluding that?
b1f6d4c to
2460ab7
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The worker response callback can break, and test environment cleanup is incorrect.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
This pull request hardens the BSON parser web worker by restricting its scope and expanding worker tests.
Changes:
- Restricts worker globals and prototypes.
- Supports direct worker URLs in tests.
- Adds worker lifecycle and security coverage.
| File | Summary |
|---|---|
packages/shell-bson-parser/src/worker.ts |
Restricts worker capabilities. Critical (3 votes): postMessage must remain available. |
packages/shell-bson-parser/src/worker-client.ts |
Adds test worker URL handling. |
packages/shell-bson-parser/src/index.spec.ts |
Expands worker behavior tests. Moderate (1 vote): delete the environment variable instead of assigning undefined. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| 'Buffer', | ||
| ]); |
2460ab7 to
b4a5690
Compare

Description
COMPASS-11128
Open Questions
Checklist
Stack created with GitHub Stacks CLI • Give Feedback 💬