From ba9a456659cc8f96509c8fededb55355acaec006 Mon Sep 17 00:00:00 2001 From: PJ Date: Sun, 3 May 2026 11:07:27 +0700 Subject: [PATCH] fix(web-runtime): enforce pressKey allowlist in factory The factory accepted any string while randomPressKey only emitted enter/tab/escape/arrows. A spec emitting pressKey({key:"home"}) would flow through to the chrome driver, which rejects unsupported keys with a runtime error mid-step. Reject at the factory so the spec author sees the failure where it originates. --- pkg/spec/src/web-runtime.ts | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkg/spec/src/web-runtime.ts b/pkg/spec/src/web-runtime.ts index ac70641..ed9a24a 100644 --- a/pkg/spec/src/web-runtime.ts +++ b/pkg/spec/src/web-runtime.ts @@ -336,6 +336,11 @@ const runtime = { return null; }, pressKey(p: { key: string }): unknown { + if (!WEB_PRESS_KEYS.includes(p.key)) { + throw new Error( + `pressKey: unsupported key ${JSON.stringify(p.key)} (allowed: ${WEB_PRESS_KEYS.join(", ")})`, + ); + } return { kind: "PressKey", key: p.key }; }, wait(p: { durationMillis: number }): unknown {