pbakaus/impeccable · error · Error
config.cspChecked, if present, must be a boolean
Error message
config.cspChecked, if present, must be a boolean
What it means
validateConfig() allows cfg.cspChecked to be omitted, but if present it must be a boolean — it records that the user confirmed the Content-Security-Policy implications of injecting a script. A truthy-looking non-boolean ('true', 1, 'yes', null) is rejected because the flag is a human confirmation, not a coerced value.
Solutions
- Use an unquoted JSON boolean: "cspChecked": true (after actually checking the page CSP)
- Or remove the key entirely when the confirmation has not happened yet
- Never bridge this with a string — the strictness is deliberate so the CSP check is a real acknowledgement
Example fix
// before "cspChecked": "true" // after "cspChecked": true
Defensive patterns
Strategy: validation
Validate before calling
if (cfg.cspChecked !== undefined && typeof cfg.cspChecked !== 'boolean') {
throw new TypeError('config.cspChecked must be a JSON boolean (true/false)');
} Type guard
const isValidCspChecked = (cfg) => cfg.cspChecked === undefined || typeof cfg.cspChecked === 'boolean';
Prevention
- Write cspChecked as an unquoted JSON boolean; never stringify values in generated configs
- Only set it to true after actually reviewing the page's Content-Security-Policy
- When converting configs between formats, assert boolean types survive the round trip
When it happens
Trigger: "cspChecked": "true" (string), 1, "yes", or null in .impeccable/live/config.json.
Common situations: Hand-editing the config and quoting the boolean; config generators that stringify all values; copying from YAML where unquoted true parses correctly but quoted 'true' does not.
Related errors
- config.commentSyntax must be 'html' or 'jsx'
- config.exclude, if present, must be a string array
- config.exclude must contain only non-empty strings
- config.files must contain only non-empty strings
- config.files (non-empty string array) required
AI-assisted analysis of pbakaus/impeccable@f88b2837a7 (2026-08-18).
Data as JSON: /api/errors/9a5e95c9b56a93a7.
Report an issue: GitHub.
Appendix: source
Thrown at skill/scripts/live-inject.mjs:472
if (!cfg.files.every((f) => typeof f === 'string' && f.length > 0)) {
throw new Error('config.files must contain only non-empty strings');
}
if (cfg.exclude !== undefined) {
if (!Array.isArray(cfg.exclude)) {
throw new Error('config.exclude, if present, must be a string array');
}
if (!cfg.exclude.every((f) => typeof f === 'string' && f.length > 0)) {
throw new Error('config.exclude must contain only non-empty strings');
}
}
if (typeof cfg.insertBefore !== 'string' && typeof cfg.insertAfter !== 'string') {
throw new Error('config.insertBefore or config.insertAfter (string) required');
}
if (cfg.commentSyntax !== 'html' && cfg.commentSyntax !== 'jsx') {
throw new Error("config.commentSyntax must be 'html' or 'jsx'");
}
if (cfg.cspChecked !== undefined && typeof cfg.cspChecked !== 'boolean') {
throw new Error("config.cspChecked, if present, must be a boolean");
}
}
// ---------------------------------------------------------------------------
// Auto-execute
// ---------------------------------------------------------------------------
const _running = process.argv[1];
if (_running?.endsWith('live-inject.mjs') || _running?.endsWith('live-inject.mjs/')) {
enterLiveRoot();
injectCli();
}
// Re-exported so long-standing importers (live.mjs, the adapter modules, the
// test suites) keep their entry points while the implementations live in
// live/frameworks/.
export {
buildLiveScriptSrc,View on GitHub (pinned to f88b2837a7)