harn-parser 0.10.58

Parser, AST, and type checker for the Harn programming language
Documentation
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
# HARN-OWN-004 — unvalidated boundary value is used directly

## How to fix

- Validate values returned by boundary APIs such as `json_parse`,
  `llm_call`, and `llm_completion` before accessing fields or indexes.
- Prefer a typed result schema at the call site when the boundary supports it,
  or pass the value through `schema_expect()` / guard it with `schema_is()`
  before property or subscript access.
- A type annotation on the binding also validates: since harn#6252 a declared
  type is checked where it is written, exactly as a declared parameter type is
  checked where it is passed. `const doc: {name: string} = json_parse(text)`
  rejects a payload whose `name` is not a string.
- Choose between them by the report you want on failure. A binding assertion
  names the binding and the declared type; `schema_expect()` names the field
  that failed and why. For a payload from outside the program, the second is
  usually worth the extra line.