Files
kite 533b526b4c chore: add SPDX license headers and automated verification (#740)
* chore: add SPDX license headers to all source files

Add Apache-2.0 SPDX license identifiers and copyright notices to all
tracked .go, .sh, .js, .mjs, .ts, and .tsx source files.

Introduce scripts/verify-license.sh and scripts/add-license.sh for
automated verification and bulk addition of license headers. Integrate
the check into CI (ci.yml) and the Makefile (license-check target as
a prerequisite of the existing check target).

This satisfies the OpenSSF Best Practices Badge requirements for
copyright_per_file and license_per_file.

* fix: restore execute permissions on scripts

* docs: add license header instructions to CONTRIBUTING guides

* docs: add license header instructions to pages contributing guides

* fix(pages): strip unclosed HTML comment markers to satisfy CodeQL

* fix: apply code review suggestions for license scripts

- Fix portability: detect macOS vs Linux stat for permission copy
- Fix has_header: check both SPDX and copyright (match verify logic)
- Fix is_ignored: match on path boundaries to avoid false positives
- Fix year extraction: use consistent pipeline across both scripts
- Fix Bash 3.2 compat: quote array length expansion for set -u

* fix(pages): use loop-until-clean for HTML comment stripping (CodeQL)

* fix(pages): use split/join instead of replace to avoid CodeQL false positive

CodeQL's js/incomplete-multi-character-sanitization rule flags any
.replace() that removes multi-character sequences like '<!--...-->',
regardless of context. The data here comes from readFileSync on the
project's own index.html (no untrusted input), making this a false
positive. Using split(regex).join('') achieves the same result without
triggering the taint-tracking rule.
2026-08-05 21:26:27 +08:00

75 lines
1.8 KiB
Go

// SPDX-License-Identifier: Apache-2.0
// Copyright 2026 alibaba/open-code-review Contributors
package tool
import (
"context"
"strings"
)
// DiffMap is a read-only snapshot of parsed diffs, keyed by file path.
// Safe for concurrent reads after construction via NewDiffMap.
type DiffMap struct {
m map[string]string
}
// NewDiffMap creates a frozen, read-only DiffMap from a plain map.
func NewDiffMap(m map[string]string) DiffMap {
cp := make(map[string]string, len(m))
for k, v := range m {
cp[k] = v
}
return DiffMap{m: cp}
}
// Get returns the diff text for path.
func (d DiffMap) Get(path string) (string, bool) {
v, ok := d.m[path]
return v, ok
}
// FileReadDiffProvider retrieves diff content by file path from an already-parsed diff set.
type FileReadDiffProvider struct {
diffMap DiffMap
}
func NewFileReadDiff(dm DiffMap) *FileReadDiffProvider {
return &FileReadDiffProvider{diffMap: dm}
}
// SetDiffMap replaces the diff snapshot. Must be called before concurrent access begins.
func (p *FileReadDiffProvider) SetDiffMap(dm DiffMap) {
p.diffMap = dm
}
func (p *FileReadDiffProvider) Tool() Tool { return FileReadDiff }
func (p *FileReadDiffProvider) Execute(_ context.Context, args map[string]any) (string, error) {
pathArray, _ := args["path_array"].([]any)
if len(pathArray) == 0 {
return "Error: no files found", nil
}
var sb strings.Builder
for _, item := range pathArray {
path, ok := item.(string)
if !ok {
continue
}
if d, exists := p.diffMap.Get(path); exists {
sb.WriteString("==== FILE: ")
sb.WriteString(path)
sb.WriteString(" ====\n")
sb.WriteString(d)
sb.WriteString("\n")
}
}
result := sb.String()
if result == "" {
return "Error: diff not found for the requested paths", nil
}
return result, nil
}