Skip to content

[ENG-4061] Resolve map bindings and helpers by scope, and report only served routes - #308

Merged
patchstackdave merged 1 commit into
mainfrom
fix/map-scope-and-routes
Sep 29, 2026
Merged

patchstackdave merged 1 commit into
mainfrom
fix/map-scope-and-routes

Conversation

@patchstackdave

Copy link
Copy Markdown
Contributor

Refs ENG-4061

The input map now resolves each identifier to the variable it refers to, instead of matching on its name. It also only reports routes the app actually serves.

Request bindings follow scope

  • A block-scoped binding, a callback parameter, or an inner function's own request that shares a name with a request binding is a different variable. It no longer proves a flow, and fields read off it are no longer inventoried as request inputs.
  • A binding that is assigned again after its declaration (plain, compound or destructuring assignment, ++/--, or a for…of head) still proves reachability, but only at transformed-local, not exact-local. The same applies to anything derived from it, and to argumentUse on dependency-input links.

Helpers follow scope

  • A call to a same-file helper reaches the helper its name resolves to. Two handlers that each define their own run now get their own sinks.
  • A local binding that shadows an imported helper is no longer followed into the import.

Routes are ones the app serves

  • A route registration needs a URL path (/… or *) as its first argument, so cache.get('user', fn) is no longer an endpoint.
  • Server actions no longer take a route from their file location. They are posted to the page that renders them.
  • Nuxt file routes come only from server/api and server/routes. server/routes/hello.ts is now /hello, not /routes/hello.

Effect on map output
Some flows move from exact-local to heuristic or transformed-local, and some endpoints lose a route or disappear. Every one of those removed coordinates was not one the app reads or serves.

Validation: full suite (3,464 passed, 7 skipped), typecheck, build. New regression tests fail on main, and each rule has its own test.

🤖 Generated with Claude Code

…ved routes

Taint roots and same-file helpers are now keyed by the declaration an
identifier resolves to, not by its name. A block-scoped binding, a
callback parameter or an inner function's own request parameter that
shares a name with a request binding is a different variable and no
longer proves a flow. A binding that is assigned again after its
declaration still proves reachability, but not an exact value.

A route registration needs a URL path as its first argument, server
actions no longer take a route from their file location, and Nuxt file
routes come only from server/api and server/routes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderbuds

coderbuds Bot commented Sep 28, 2026

Copy link
Copy Markdown

Implements correct scope-based binding resolution and filters only served routes.

🎯 Quality: 84% Excellent · 📦 Size: Extra Large — strongly consider breaking this down

🛡️ Standards: Not checked — 654 lines changed, over your team's 400-line limit, and nothing checked before it was opened. Coding agents can call the assess-change-fit tool first, while a change this size is still cheap to split.

📈 This month: Your 159th PR — above team average · Averaging Good

See how your team is trending →

@patchstackdave

Copy link
Copy Markdown
Contributor Author

/review

@patchstackdave
patchstackdave merged commit 1e821ad into main Sep 29, 2026
18 checks passed
@patchstackdave
patchstackdave deleted the fix/map-scope-and-routes branch September 29, 2026 09:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants