{"record":{"id":"d8484293d2877d68","repo":"siyuan-note/siyuan","slug":"invalid-package-name-d84842","errorCode":null,"errorMessage":"invalid package name","messagePattern":"invalid package name","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/model/bazaar_rating.go","lineNumber":231,"sourceCode":"\t}\n\tdistribution := [5]int64(data.Distribution)\n\tif 0 < data.Rating && 1 > distribution[data.Rating-1] {\n\t\treturn nil, false, 0, errors.New(\"invalid rating distribution returned by cloud server\")\n\t}\n\tif !bazaar.ApplyBazaarPackageRatingDistribution(region, packageName, distribution) {\n\t\treturn nil, false, 0, errors.New(\"invalid rating distribution returned by cloud server\")\n\t}\n\n\trating, ratingAvailable = bazaarRatingAfterUpdate(ctx, region, packageName, distribution)\n\treturn rating, ratingAvailable, data.Rating, nil\n}\n\nfunc validateBazaarPackageRatingRequest0(ctx context.Context, pkgType, packageName string) (token string, err error) {\n\tif !isValidBazaarPackageType(pkgType) {\n\t\treturn \"\", errors.New(\"invalid package type\")\n\t}\n\tif !bazaar.IsValidPackageName(packageName) {\n\t\treturn \"\", errors.New(\"invalid package name\")\n\t}\n\ttoken, err = bazaarRatingUserToken()\n\tif nil != err {\n\t\treturn \"\", err\n\t}\n\n\tinstalledInfos, _, _, err := GetInstalledPackageInfos(pkgType)\n\tif nil != err {\n\t\treturn \"\", err\n\t}\n\tinstalled := false\n\tfor _, info := range installedInfos {\n\t\tif \"\" == info.Pkg.InvalidReason && packageName == info.Pkg.Name {\n\t\t\tinstalled = true\n\t\t\tbreak\n\t\t}\n\t}\n\tif !installed {","sourceCodeStart":213,"sourceCodeEnd":249,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/bazaar_rating.go#L213-L249","documentation":"validateBazaarPackageRatingRequest0 rejects package names that fail bazaar.IsValidPackageName before any cloud request (kernel/model/bazaar_rating.go:230-231). A valid marketplace package name is a sanitized identifier (repo-style name); empty strings, names with path separators, whitespace, or control characters are rejected.","triggerScenarios":"Calling GetBazaarPackageRating or SetBazaarPackageRating with packageName = \"\", a name containing '/' or whitespace, a display name instead of the package identifier, or a name carrying a version suffix.","commonSituations":"Passing the human-readable package title rather than its repo name; including the author prefix inconsistently; trimming/validation missing on a user-supplied input in a plugin or script; path traversal attempts.","solutions":["Pass the exact package identifier as listed in the marketplace (e.g. the repo name), not the display title","Trim whitespace and verify the name is non-empty and contains no '/' or special characters before calling","Pre-validate with bazaar.IsValidPackageName(name) to fail fast with a clearer message","Use the package name from installed package metadata (info.Pkg.Name) rather than user input"],"exampleFix":"// before\nmodel.SetBazaarPackageRating(ctx, \"plugins\", \"My Cool Plugin/1.0\", 5)\n// after\nname := \"siyuan-plugin-foo\"\nif !bazaar.IsValidPackageName(name) { return errors.New(\"bad package name\") }\nmodel.SetBazaarPackageRating(ctx, \"plugins\", name, 5)","handlingStrategy":"validation","validationCode":"func validPkgName(name string) bool { return name != \"\" && bazaar.IsValidPackageName(name) }","typeGuard":null,"tryCatchPattern":"if !bazaar.IsValidPackageName(packageName) {\n    return fmt.Errorf(\"package name %q is not a valid marketplace identifier\", packageName)\n}","preventionTips":["Pass the marketplace identifier (repo-style name), never the display title","Strip version suffixes and author prefixes not part of the canonical name","Read the name from installed package metadata (info.Pkg.Name) instead of free-text input","Pre-validate with bazaar.IsValidPackageName before any cloud rating call"],"tags":["go","validation","marketplace","invalid-argument"],"backgroundTag":"invalid-identifier-format","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}