fix(mailbox): validate bot list limits

This commit is contained in:
rissrice2105-agent 2026-07-04 17:13:08 -06:00
parent 6a086eb7cc
commit b571732d5b
2 changed files with 25 additions and 1 deletions

View file

@ -53,7 +53,11 @@ func RunBot(ctx context.Context, c *Client, args []string, in io.Reader, out io.
}
limit := 0
if len(args) > 2 {
limit, _ = strconv.Atoi(args[2])
n, err := strconv.Atoi(args[2])
if err != nil || n <= 0 {
return fail(fmt.Errorf("invalid list limit %q", args[2]))
}
limit = n
}
v, err := c.List(ctx, mailbox, limit)
if err != nil {

View file

@ -1,8 +1,10 @@
package mailbox
import (
"bytes"
"context"
"errors"
"strings"
"testing"
"time"
@ -210,3 +212,21 @@ func TestFlagAndDelete(t *testing.T) {
t.Fatal("uid 1 should be deleted")
}
}
func TestRunBotListRejectsInvalidLimit(t *testing.T) {
c := paidClient(seeded())
for _, args := range [][]string{
{"list", Inbox, "nope"},
{"list", Inbox, "-5"},
} {
var out bytes.Buffer
err := RunBot(context.Background(), c, args, strings.NewReader(""), &out)
if err == nil {
t.Fatalf("RunBot(%v) expected error", args)
}
if !strings.Contains(out.String(), "invalid list limit") {
t.Fatalf("RunBot(%v) output = %q, want invalid limit error", args, out.String())
}
}
}