Skip to content

fix(slideshow): validate nested hotspot entries - #5211

Merged
jrusso1020 merged 1 commit into
heygen-com:mainfrom
user-github-me:fix/slideshow-hotspot-validation
Oct 8, 2026
Merged

jrusso1020 merged 1 commit into
heygen-com:mainfrom
user-github-me:fix/slideshow-hotspot-validation

Conversation

@user-github-me

Copy link
Copy Markdown
Contributor

A parseable slideshow island containing "hotspots": [null] currently passes the manifest guard and crashes hyperframes lint with Cannot read properties of null (reading 'target'). Other malformed entries can survive resolution and be classified as ready by the player.

Validate each hotspot in the shared parser: require an object with string id, label, and target, and validate the four finite numeric coordinates when a region is present. Both main-line and branch slides use the guard. This lets lint report its existing slideshow_invalid finding and the player classify the existing malformed-island state before initialization.

Validation:

  • Parser regressions cover malformed main-line/branch hotspots, optional arrays, valid regions, and overflowing JSON numbers. Initial regressions fail on main in the parser, lint, and player.
  • Full parser suite: 1,245 passed, 4 skipped, 3 TODO. Full lint suite: 837 passed. Slideshow player suites: 150 passed. CLI project/command/format suites: 99 passed.
  • All 214 shipped example/block compositions retain byte-identical lint findings.
  • Built CLI returns exactly one structured error for the malformed fixture, and the valid control passes strict lint/check with all five contrast samples passing.
  • Chrome 152 with the built global bundle: malformed hotspot changes from ready to malformed-island; the valid control stays ready.
  • Parser, lint, player, and CLI builds/typechecks, player runtime-pin verification, repository lint/formatting, pre-commit gates, comment checks, deletion guard, and test reachability passed.

This completes nested hotspot shape validation beside the manifest guards added in #1585 and #1594.

@jrusso1020 jrusso1020 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Confirmed on main: a slideshow island with "hotspots": [null] passes the manifest guard and then crashes resolveSlideshow when it reads h.target, so lint throws instead of reporting slideshow_invalid. The shared parser is the right place to validate each hotspot, and it matches the existing manifest guards. Requiring numeric region values also stops non-numbers from being written into the pill's inline style. The new parser tests fail on main and pass here. Looks good.

— Rames

@jrusso1020
jrusso1020 enabled auto-merge October 8, 2026 19:38
@jrusso1020
jrusso1020 added this pull request to the merge queue Oct 8, 2026
Merged via the queue into heygen-com:main with commit 00729a5 Oct 8, 2026
83 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants