affaan-m/ECC · error

must not contain control or bidirectional formatting…

Error message

${label} must not contain control or bidirectional formatting characters.

What it means

After trimming and length checks, asNonEmptyString scans for unsafe control characters and bidirectional formatting characters (e.g. U+202E RTL overrides) that could corrupt display or enable Trojan-source style spoofing. Any validated memory-vault string containing them is rejected.

Solutions

  1. Strip control and bidi characters from the input, e.g. value.replace(/[\u0000-\u001F\u007F\u200B-\u200F\u202A-\u202E]/g, '').
  2. Sanitize user input at the boundary before passing to the vault.
  3. Re-copy the text from a clean source if it was pasted from a PDF/terminal.
  4. For bidi content, store a plain-text normalization rather than raw directional marks.

Example fix

// before
asNonEmptyString(pastedText, 'content')
// after
const clean = pastedText.replace(/[\u0000-\u0008\u000B\u000C\u000E-\u001F\u007F\u200B-\u200F\u202A-\u202E]/g, '')
asNonEmptyString(clean, 'content')
Defensive patterns

Strategy: validation

Validate before calling

// eslint-disable-next-line no-control-regex
const UNSAFE = /[\u0000-\u0008\u000B\u000C\u000E-\u001F\u007F\u200B-\u200F\u202A-\u202E]/g
const sanitized = String(raw).replace(UNSAFE, '')

Type guard

function isSafeText(v) {
  // eslint-disable-next-line no-control-regex
  return typeof v === 'string' && !/[\u0000-\u0008\u000B\u000C\u000E-\u001F\u007F\u200B-\u200F\u202A-\u202E]/.test(v)
}

Try / catch

try {
  asNonEmptyString(value, 'content')
} catch (err) {
  if (err.message.includes('control or bidirectional')) {
    value = value.replace(/[\u0000-\u0008\u000B\u000C\u000E-\u001F\u007F\u200B-\u200F\u202A-\u202E]/g, '')
  } else throw err
}

Prevention

When it happens

Trigger: Passing a string containing control characters (e.g. \u0000-\u001F other than allowed whitespace, \u007F) or bidi marks (\u200F, \u202E, etc.) to asNonEmptyString via normalizeMemory or resolveOverride.

Common situations: Pasting text from PDFs or terminals that embed control characters; malicious input crafted with RTL overrides to reverse visual display; binary data accidentally decoded as a string; filenames or logs copied with stray \x1b escape sequences.

Understand the failure class

Background: "Invalid ... format", "must be in format X", "does not look like a ..." — invalid argument format errors across CLI tools and libraries — this error's family across 17 libraries.

Related errors


AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16). Data as JSON: /api/errors/2efe4998e8dbc35d. Report an issue: GitHub.

Appendix: source

Thrown at scripts/lib/memory-vault-format.js:86

      || (codePoint >= 0x7f && codePoint <= 0x9f);
    const isBidirectionalFormatting = (
      (codePoint >= 0x202a && codePoint <= 0x202e)
      || (codePoint >= 0x2066 && codePoint <= 0x2069)
    );
    return isControl || isBidirectionalFormatting;
  });
}

function asNonEmptyString(value, label, maxChars = 10_000) {
  if (typeof value !== 'string' || value.trim().length === 0) {
    throw new Error(`${label} must be a non-empty string.`);
  }
  const normalized = value.trim();
  if (normalized.length > maxChars) {
    throw new Error(`${label} is too long (maximum ${maxChars} characters).`);
  }
  if (hasUnsafeControlCharacters(normalized)) {
    throw new Error(`${label} must not contain control or bidirectional formatting characters.`);
  }
  return normalized;
}

function validateEnum(value, allowed, label) {
  const normalized = asNonEmptyString(value, label, 64);
  if (!allowed.includes(normalized)) {
    throw new Error(`${label} must be one of: ${allowed.join(', ')}.`);
  }
  return normalized;
}

function validateSlug(value, label) {
  const normalized = asNonEmptyString(value, label, 64);
  if (!SLUG_PATTERN.test(normalized)) {
    throw new Error(`${label} must be a lowercase letters/numbers slug.`);
  }
  return normalized;

View on GitHub (pinned to 8321021c54)