Skip to content

fix(hooks): validate stored recently-viewed IDs are strings and respect cap (#1972) - #1997

Draft
s6pa1rta3n-lab wants to merge 1 commit into
Commitlabs-Org:masterfrom
s6pa1rta3n-lab:fix-issue-1972
Draft

s6pa1rta3n-lab wants to merge 1 commit into
Commitlabs-Org:masterfrom
s6pa1rta3n-lab:fix-issue-1972

Conversation

@s6pa1rta3n-lab

Copy link
Copy Markdown

Description

Resolves an issue where readStoredRecentIds did not validate that elements in the stored array were strings, and ensures the cap parameter is respected when slicing items from storage.

Changes Made

  • Filtered parsed stored items strictly to entries where typeof item === 'string'.
  • Updated array slicing in readStoredRecentIds to use cap instead of hardcoded MAX_RECENT_LISTINGS.
  • Added unit tests covering corrupted localStorage arrays with non-string elements (numbers, booleans, objects, null, undefined).
  • Added unit tests covering unparseable JSON and non-array JSON in localStorage.
  • Added unit tests validating initial cap enforcement and error handling for storage access exceptions.

Issue Reference

Closes #1972

PR Checklist

  • Code follows project style guidelines
  • Self-review completed
  • Documentation updated (if applicable)
  • Tests added/updated
  • All tests passing locally
  • No new console warnings
  • Bundle size impact considered

Payout Routing

  • EVM (Base/Arbitrum/Polygon/ETH): 0xF46C9F6d70C50BF81ef3588AB523a90a594a2F89
  • Stellar: GCL6OXAMLD75BMTINA6EMRUDWK5THQUSHMYNLSNBCJAPZJHNYJTUNIBC

@vercel

vercel Bot commented Sep 28, 2026

Copy link
Copy Markdown

@s6pa1rta3n-lab is attempting to deploy a commit to the 1nonly's projects Team on Vercel.

A member of the Team first needs to authorize it.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

useRecentlyViewed doesn't validate that stored recently-viewed IDs are actually strings

1 participant