Area: sdk · codegen CLI — footgun · found via PM triage of the --tenant work merged in #729
Expected: wavehouse-codegen refuses an argument it does not recognize, so a mistyped flag cannot be mistaken for a flag that was honored.
Actual: parseArgs (clients/ts/src/cli/codegen.ts:54-96) is a switch over the argument with no default: case, so any argument that is not one of the ten known flags is skipped without a word. Measured against bf88dbab by calling the exported parseArgs directly:
| argv |
parsed |
--tenant acme |
tenant: "acme" |
--tenat acme |
(no tenant) |
--tenant-id acme |
(no tenant) |
-T acme |
(no tenant) |
--operator-ket k --tenant acme |
tenant: "acme", no operator key |
acme |
(nothing) |
--out (no value) |
throws --out needs a file path |
The operand() guard added in #729 covers a missing, empty, or flag-valued operand. It cannot see a flag whose name is wrong, because such an argument never reaches a case.
Impact: --tenant's whole purpose (#640, #729) is to read a named tenant of a nested settings directory. A typo in it does not fail — it silently falls back to tenant 0. Codegen then exits 0, prints ✓ Types written to …, and the committed .d.ts describes the wrong tenant's tables. The user gets no signal at generation time; the mismatch surfaces later as type errors against real data, or not at all when the two tenants' schemas overlap. A mistyped --operator-key is dropped the same way: on a nested directory the request then carries no credential and 403s loudly, but on a flat directory it can succeed against the default tenant.
The same silence swallows a bare positional (wavehouse-codegen out.d.ts writes ./wavehouse.d.ts) and any --flag=value form, which this parser does not accept at all.
Scope: a default: arm in the same switch.
Related: #640 (the --tenant gap this follows), #527, #528 (the other two open issues on this file)
From a codebase read during the PM-triage routine; validated by running the exported parseArgs against origin/main at bf88dbab on 2026-10-07.
Area: sdk · codegen CLI — footgun · found via PM triage of the
--tenantwork merged in #729Expected:
wavehouse-codegenrefuses an argument it does not recognize, so a mistyped flag cannot be mistaken for a flag that was honored.Actual:
parseArgs(clients/ts/src/cli/codegen.ts:54-96) is aswitchover the argument with nodefault:case, so any argument that is not one of the ten known flags is skipped without a word. Measured againstbf88dbabby calling the exportedparseArgsdirectly:--tenant acmetenant: "acme"--tenat acme--tenant-id acme-T acme--operator-ket k --tenant acmetenant: "acme", no operator keyacme--out(no value)--out needs a file pathThe
operand()guard added in #729 covers a missing, empty, or flag-valued operand. It cannot see a flag whose name is wrong, because such an argument never reaches acase.Impact:
--tenant's whole purpose (#640, #729) is to read a named tenant of a nested settings directory. A typo in it does not fail — it silently falls back to tenant0. Codegen then exits0, prints✓ Types written to …, and the committed.d.tsdescribes the wrong tenant's tables. The user gets no signal at generation time; the mismatch surfaces later as type errors against real data, or not at all when the two tenants' schemas overlap. A mistyped--operator-keyis dropped the same way: on a nested directory the request then carries no credential and403s loudly, but on a flat directory it can succeed against the default tenant.The same silence swallows a bare positional (
wavehouse-codegen out.d.tswrites./wavehouse.d.ts) and any--flag=valueform, which this parser does not accept at all.Scope: a
default:arm in the sameswitch.Related: #640 (the
--tenantgap this follows), #527, #528 (the other two open issues on this file)From a codebase read during the PM-triage routine; validated by running the exported
parseArgsagainstorigin/mainatbf88dbabon 2026-10-07.