{"record":{"id":"9a5e95c9b56a93a7","repo":"pbakaus/impeccable","slug":"config-cspchecked-if-present-must-be-a-boolean","errorCode":null,"errorMessage":"config.cspChecked, if present, must be a boolean","messagePattern":"config\\.cspChecked, if present, must be a boolean","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"skill/scripts/live-inject.mjs","lineNumber":472,"sourceCode":"  if (!cfg.files.every((f) => typeof f === 'string' && f.length > 0)) {\n    throw new Error('config.files must contain only non-empty strings');\n  }\n  if (cfg.exclude !== undefined) {\n    if (!Array.isArray(cfg.exclude)) {\n      throw new Error('config.exclude, if present, must be a string array');\n    }\n    if (!cfg.exclude.every((f) => typeof f === 'string' && f.length > 0)) {\n      throw new Error('config.exclude must contain only non-empty strings');\n    }\n  }\n  if (typeof cfg.insertBefore !== 'string' && typeof cfg.insertAfter !== 'string') {\n    throw new Error('config.insertBefore or config.insertAfter (string) required');\n  }\n  if (cfg.commentSyntax !== 'html' && cfg.commentSyntax !== 'jsx') {\n    throw new Error(\"config.commentSyntax must be 'html' or 'jsx'\");\n  }\n  if (cfg.cspChecked !== undefined && typeof cfg.cspChecked !== 'boolean') {\n    throw new Error(\"config.cspChecked, if present, must be a boolean\");\n  }\n}\n\n// ---------------------------------------------------------------------------\n// Auto-execute\n// ---------------------------------------------------------------------------\n\nconst _running = process.argv[1];\nif (_running?.endsWith('live-inject.mjs') || _running?.endsWith('live-inject.mjs/')) {\n  enterLiveRoot();\n  injectCli();\n}\n\n// Re-exported so long-standing importers (live.mjs, the adapter modules, the\n// test suites) keep their entry points while the implementations live in\n// live/frameworks/.\nexport {\n  buildLiveScriptSrc,","sourceCodeStart":454,"sourceCodeEnd":490,"githubUrl":"https://github.com/pbakaus/impeccable/blob/f88b2837a7d7c3182e46307bbbb091a1ed547571/skill/scripts/live-inject.mjs#L454-L490","documentation":"validateConfig() allows cfg.cspChecked to be omitted, but if present it must be a boolean — it records that the user confirmed the Content-Security-Policy implications of injecting a script. A truthy-looking non-boolean ('true', 1, 'yes', null) is rejected because the flag is a human confirmation, not a coerced value.","triggerScenarios":"\"cspChecked\": \"true\" (string), 1, \"yes\", or null in .impeccable/live/config.json.","commonSituations":"Hand-editing the config and quoting the boolean; config generators that stringify all values; copying from YAML where unquoted true parses correctly but quoted 'true' does not.","solutions":["Use an unquoted JSON boolean: \"cspChecked\": true (after actually checking the page CSP)","Or remove the key entirely when the confirmation has not happened yet","Never bridge this with a string — the strictness is deliberate so the CSP check is a real acknowledgement"],"exampleFix":"// before\n\"cspChecked\": \"true\"\n\n// after\n\"cspChecked\": true","handlingStrategy":"validation","validationCode":"if (cfg.cspChecked !== undefined && typeof cfg.cspChecked !== 'boolean') {\n  throw new TypeError('config.cspChecked must be a JSON boolean (true/false)');\n}","typeGuard":"const isValidCspChecked = (cfg) =>\n  cfg.cspChecked === undefined || typeof cfg.cspChecked === 'boolean';","tryCatchPattern":null,"preventionTips":["Write cspChecked as an unquoted JSON boolean; never stringify values in generated configs","Only set it to true after actually reviewing the page's Content-Security-Policy","When converting configs between formats, assert boolean types survive the round trip"],"tags":["config","schema","boolean","csp","live-inject"],"backgroundTag":"config-schema-validation","analyzedSha":"f88b2837a7d7c3182e46307bbbb091a1ed547571","analyzedAt":"2026-08-18T04:58:36.608Z","contentChangedAt":"2026-08-18T04:58:36.608Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}