Skip to content

[deeplink] add safe guards around api request - #10022

Merged
chunhtai merged 7 commits into
flutter:masterfrom
chunhtai:santize-deeplink-input
Sep 30, 2026
Merged

chunhtai merged 7 commits into
flutter:masterfrom
chunhtai:santize-deeplink-input

Conversation

@chunhtai

@chunhtai chunhtai commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

This pr rejects unrecongized build variants as well as pass in package root path.

related b/555370339

Pre-launch Checklist

General checklist

  • I read the Contributor Guide and followed the process outlined there for submitting PRs.
  • I read the Tree Hygiene wiki page, which explains my responsibilities.
  • I read the Flutter Style Guide recently, and have followed its advice.
  • I signed the CLA.
  • I updated/added relevant documentation (doc comments with ///).

Issues checklist

Tests checklist

  • I added new tests to check the change I am making...
  • OR there is a reason for not adding tests, which I explained in the PR description.

AI-tooling checklist

  • I did not use any AI tooling in creating this PR.
  • OR I did use AI tooling, and...
    • I read the AI contributions guidelines and agree to follow them.
    • I reviewed all AI-generated code before opening this PR.
    • I understand and am able to discuss the code in this PR.
    • I have verifed the accuracy of any AI-generated text included in the PR description.
    • I commit to verifying the accuracy of any AI-generated code or text that I upload in response to review comments.

Feature-change checklist

  • This PR does not change the DevTools UI or behavior and...
    • I added the release-notes-not-required label or left a comment requesting the label be added.
  • OR this PR does change the DevTools UI or behavior and...
    • I added an entry to packages/devtools_app/release_notes/NEXT_RELEASE_NOTES.md.
    • I included before/after screenshots and/or a GIF demo of the new UI to my PR description.
    • I ran the DevTools app locally to manually verify my changes.

build.yaml badge

If you need help, consider asking for help on Discord.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces caching for Android build variants and iOS Xcode build options within DeeplinkManager, enabling validation of build variants, configurations, and targets before executing Flutter commands. Additionally, it updates process execution to run within the project's root directory rather than passing the path as an argument. The review feedback identifies two critical issues where JSON parsing errors during cache population are silently ignored, which can result in misleading error messages during subsequent validation steps. It is recommended to catch these exceptions and return descriptive error maps.

Comment thread packages/devtools_shared/lib/src/deeplink/deeplink_manager.dart
Comment thread packages/devtools_shared/lib/src/deeplink/deeplink_manager.dart
@chunhtai
chunhtai requested a review from a team as a code owner September 29, 2026 18:40
@chunhtai
chunhtai requested review from srawlins and removed request for a team September 29, 2026 18:40
assert(controller.currentAppLinkSettings?.error != null);
final error = [
controller.currentAppLinkSettings?.error,
controller.currentUniversalLinkSettings?.error,

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since this pr introduced a new way things can return error, I make sure both android and ios error will surface to the ui.

///
/// Populated by [getAndroidBuildVariants] and used to validate `buildVariant`
/// in [getAndroidAppLinkSettings].
static final _androidBuildVariantsCache = <String, Set<String>>{};

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This unfortunately means the server api handler will be stateful, but this is needed to filter bad request

return _runFlutterCommand(
<String>['analyze', '--android', '--list-build-variants', rootPath],
<String>['analyze', '--android', '--list-build-variants'],
workingDirectory: rootPath,

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

convert to use working directory to avoid bad path or non path argument.

@srawlins srawlins left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, love the tests

@chunhtai
chunhtai merged commit efbfeba into flutter:master Sep 30, 2026
51 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants