Files
ccs/docs/reports/hardening-inventory.json
T

788 lines
23 KiB
JSON

{
"scope": "src/**/*.{ts,tsx,js,jsx,mjs,cjs}",
"syncFs": {
"totalOccurrences": 2513,
"filesAffected": 263,
"hotpathOccurrences": 1183,
"hotpathFilesAffected": 156,
"topHotpathFiles": [
{
"file": "src/utils/browser/mcp-installer.ts",
"count": 32,
"calls": [
"chmodSync",
"copyFileSync",
"existsSync",
"mkdirSync",
"readFileSync",
"renameSync",
"statSync",
"unlinkSync",
"writeFileSync"
],
"markers": []
},
{
"file": "src/utils/image-analysis/mcp-installer.ts",
"count": 30,
"calls": [
"chmodSync",
"copyFileSync",
"existsSync",
"mkdirSync",
"readFileSync",
"renameSync",
"statSync",
"unlinkSync",
"writeFileSync"
],
"markers": []
},
{
"file": "src/management/shared-manager/diverged-file-adopter.ts",
"count": 29,
"calls": [
"chmodSync",
"closeSync",
"fsyncSync",
"linkSync",
"lstatSync",
"openSync",
"readdirSync",
"readFileSync",
"readlinkSync",
"renameSync",
"statSync",
"unlinkSync",
"writeFileSync"
],
"markers": []
},
{
"file": "src/utils/claude-symlink-manager.ts",
"count": 27,
"calls": [
"copyFileSync",
"existsSync",
"lstatSync",
"mkdirSync",
"readdirSync",
"readlinkSync",
"renameSync",
"rmSync",
"statSync",
"symlinkSync",
"unlinkSync"
],
"markers": []
},
{
"file": "src/cliproxy/config/env-builder.ts",
"count": 25,
"calls": [
"existsSync",
"mkdirSync",
"readFileSync",
"writeFileSync"
],
"markers": []
},
{
"file": "src/management/shared-manager/migrations.ts",
"count": 25,
"calls": [
"copyFileSync",
"cpSync",
"existsSync",
"lstatSync",
"mkdirSync",
"readdirSync",
"symlinkSync",
"unlinkSync",
"writeFileSync"
],
"markers": []
},
{
"file": "src/utils/websearch/mcp-installer.ts",
"count": 25,
"calls": [
"chmodSync",
"copyFileSync",
"existsSync",
"mkdirSync",
"readFileSync",
"renameSync",
"statSync",
"unlinkSync",
"writeFileSync"
],
"markers": []
},
{
"file": "src/cliproxy/services/variant-settings.ts",
"count": 23,
"calls": [
"existsSync",
"mkdirSync",
"readFileSync",
"renameSync",
"unlinkSync",
"writeFileSync"
],
"markers": []
},
{
"file": "src/management/recovery-manager.ts",
"count": 23,
"calls": [
"copyFileSync",
"existsSync",
"lstatSync",
"mkdirSync",
"renameSync",
"statSync",
"unlinkSync",
"writeFileSync"
],
"markers": []
},
{
"file": "src/utils/shell-completion.ts",
"count": 23,
"calls": [
"appendFileSync",
"copyFileSync",
"existsSync",
"mkdirSync",
"readFileSync",
"statSync"
],
"markers": []
}
],
"topFilesOverall": [
{
"file": "src/cliproxy/__tests__/pool-routing-phase3.test.ts",
"count": 96,
"calls": [
"existsSync",
"mkdirSync",
"mkdtempSync",
"readFileSync",
"rmSync",
"writeFileSync"
],
"markers": []
},
{
"file": "src/cliproxy/config/__tests__/config-generator.test.js",
"count": 88,
"calls": [
"existsSync",
"mkdirSync",
"mkdtempSync",
"readFileSync",
"rmSync",
"writeFileSync"
],
"markers": []
},
{
"file": "src/cliproxy/config/__tests__/claude-model-neutral.test.ts",
"count": 63,
"calls": [
"existsSync",
"mkdirSync",
"mkdtempSync",
"readFileSync",
"rmSync",
"statSync",
"writeFileSync"
],
"markers": []
},
{
"file": "src/cliproxy/accounts/__tests__/account-safety-quota-exhaustion.test.ts",
"count": 48,
"calls": [
"existsSync",
"mkdirSync",
"mkdtempSync",
"readFileSync",
"rmSync",
"writeFileSync"
],
"markers": []
},
{
"file": "src/cliproxy/accounts/__tests__/account-registry-integrity.test.ts",
"count": 45,
"calls": [
"existsSync",
"mkdirSync",
"mkdtempSync",
"readdirSync",
"readFileSync",
"rmSync",
"writeFileSync"
],
"markers": []
},
{
"file": "src/cliproxy/binary/__tests__/binary-installer-atomic.test.ts",
"count": 41,
"calls": [
"existsSync",
"mkdirSync",
"mkdtempSync",
"readdirSync",
"readFileSync",
"renameSync",
"rmdirSync",
"rmSync",
"writeFileSync"
],
"markers": []
},
{
"file": "src/cliproxy/executor/__tests__/variant-port-integration.test.js",
"count": 36,
"calls": [
"existsSync",
"mkdirSync",
"readdirSync",
"readFileSync",
"rmSync",
"unlinkSync",
"writeFileSync"
],
"markers": []
},
{
"file": "src/cliproxy/executor/__tests__/composite-variant-service.test.ts",
"count": 33,
"calls": [
"existsSync",
"mkdirSync",
"mkdtempSync",
"readFileSync",
"rmSync",
"writeFileSync"
],
"markers": []
},
{
"file": "src/cliproxy/executor/__tests__/variant-port-edge-cases.test.js",
"count": 33,
"calls": [
"existsSync",
"mkdirSync",
"readdirSync",
"rmSync",
"unlinkSync",
"writeFileSync"
],
"markers": []
},
{
"file": "src/utils/browser/mcp-installer.ts",
"count": 32,
"calls": [
"chmodSync",
"copyFileSync",
"existsSync",
"mkdirSync",
"readFileSync",
"renameSync",
"statSync",
"unlinkSync",
"writeFileSync"
],
"markers": []
}
]
},
"legacyShim": {
"totalMarkers": 465,
"filesAffected": 176,
"topFiles": [
{
"file": "src/auth/profile-detector.ts",
"count": 18,
"calls": [],
"markers": [
"? `Using legacy API profile \"${candidate}\" for \"${profileName}\".`",
"' 1. Run: ccs legacy cursor enable\\n' +",
"' 2. Import auth: ccs legacy cursor auth\\n' +",
"' 3. Start daemon: ccs legacy cursor start\\n\\n' +",
"'Legacy Cursor profile is not enabled.\\n\\n' +",
"* - Legacy JSON format (config.json, profiles.json) as fallback",
"* 2. User-defined CLIProxy variants (config.cliproxy section) [legacy]",
"* 3. Settings-based profiles (config.profiles section) [legacy]",
"* 4. Account-based profiles (profiles.json) [legacy]",
"* Priority: settings-based profiles (glm/km) checked FIRST for backward compatibility.",
"// Check if account-based default exists (legacy)",
"// Fall back to legacy config",
"// Fall back to legacy config display",
"// Fall through to legacy if not found in unified config",
"// Priority 0.25: Check explicit legacy Cursor bridge profile.",
"// Priority 3: Check settings-based profiles (glm, km) - LEGACY FALLBACK",
"// Priority 4: Check account-based profiles (work, personal) - LEGACY FALLBACK"
]
},
{
"file": "src/web-server/usage/native-quota-collector.ts",
"count": 15,
"calls": [],
"markers": [
"* are used for backward compatibility.",
"* Kept for backward compatibility with existing tests.",
"* Legacy Codex collector — uses the old getDefaultCodexAccountId dep.",
"* List all Claude profiles from the profile registry (merged legacy + unified).",
"* profile name. Kept for backward compatibility with existing tests that stub",
"* When no enumeration deps are injected (legacy mode / old tests that stub only",
"/** Legacy Codex network row builder. */",
"/** Legacy Codex row builder (local quota). */",
"/** Legacy row builder — no surface/profile/is_subscription fields. */",
"// everything except the legacy harness takes the multi-profile path below.",
"// For the network fallback: the legacy getDefaultCodexAccountId is the",
"// Legacy path: backward-compatible with old tests that only inject",
"// Legacy single-profile collectors (unchanged; used by old tests + back-compat)",
"// Multi-profile enumeration is the DEFAULT (production) behavior. The legacy",
"// Use the legacy single-state approach via profile key '__legacy__' to avoid"
]
},
{
"file": "src/utils/config-manager.ts",
"count": 13,
"calls": [],
"markers": [
"* Get config file path (legacy JSON path)",
"* Precedence: --config-dir flag > CCS_DIR env > CCS_HOME env (legacy, appends .ccs) > ~/.ccs default",
"* Read and parse config (legacy compatibility)",
"* Returns Config with profiles from unified config.yaml or legacy config.json.",
"* Returns config.yaml in unified mode, config.json in legacy mode.",
"* then falls back to config.json for backward compatibility.",
"// Convert unified cliproxy variants to legacy format",
"// Convert unified profiles to legacy format for compatibility",
"// If not found in unified config, try legacy config.json as fallback",
"// Legacy config is invalid JSON - that's OK in unified mode",
"// Legacy mode - read from config.json only",
"// Legacy mode: read config.json",
"// Merge legacy profiles into available list (avoid duplicates)"
]
},
{
"file": "src/cliproxy/__tests__/pool-onboarding-phase5.test.ts",
"count": 12,
"calls": [],
"markers": [
"* 12. Legacy-only install: dismissOnboardingHint does not create config.yaml",
"* 14. Legacy-only install: hasUnifiedConfig() returns false, enforcing call-site gate",
"/** Create a legacy-only home: has profiles.json but NO config.yaml */",
"// ── 12. Legacy-only install: dismissal does not create config.yaml ────────",
"// ── 14. Legacy-only install: hasUnifiedConfig() is false at account-flow / create-command sites ──",
"// Intentionally no config.yaml - legacy install",
"// meaning those call sites silently skip the hint and legacy users receive",
"// Override tempHome with a legacy-only home (no config.yaml)",
"// The call-site guard must return false - legacy install has no config.yaml",
"const dir = fs.mkdtempSync(path.join(os.tmpdir(), 'ccs-pool-onboarding-legacy-'));",
"it('dismissOnboardingHint does not create config.yaml for legacy profiles.json-only installs', async () => {",
"it('hasUnifiedConfig returns false for legacy profiles.json-only installs (call-site gate)', async () => {"
]
},
{
"file": "src/cliproxy/executor/__tests__/variant-port-allocation.test.js",
"count": 12,
"calls": [],
"markers": [
"// Create legacy variant without port",
"// Create variant without port (legacy format)",
"// Should return first port since legacy variant has no port",
"assert.strictEqual(variants.legacy.port, undefined);",
"assert.strictEqual(variants.legacy.provider, 'gemini');",
"describe('getNextAvailablePort - Legacy Variant Handling', function () {",
"it('handles mixed legacy and modern variants', function () {",
"it('returns undefined port for legacy variants', function () {",
"legacy: {",
"settings: path.join(ccsDir, 'legacy.settings.json'),"
]
},
{
"file": "src/config/schemas/websearch.ts",
"count": 10,
"calls": [],
"markers": [
"* Legacy AI CLI fallbacks remain available for compatibility only.",
"* Uses deterministic search backends first, with optional legacy CLI fallback.",
"/** Enable Gemini CLI legacy fallback (default: false) */",
"/** Enable Grok CLI legacy fallback (default: false - requires GROK_API_KEY) */",
"/** Enable OpenCode CLI legacy fallback (default: false) */",
"/** Gemini CLI - deprecated legacy LLM fallback (retired upstream) */",
"/** Grok CLI - optional legacy LLM fallback */",
"/** Model to use (default: gemini-2.5-flash; accepts legacy gemini ids) */",
"/** OpenCode - optional legacy LLM fallback */",
"// Legacy fields (deprecated, kept for backwards compatibility)"
]
},
{
"file": "src/commands/cursor-command-display.ts",
"count": 9,
"calls": [],
"markers": [
"' disable Disable legacy cursor integration in unified config',",
"' enable Enable legacy cursor integration in unified config',",
"' status Show legacy integration, authentication, and daemon status',",
"'Legacy auth options:',",
"'Legacy bridge quick start:',",
"'Legacy Cursor Compatibility',",
"'Legacy runtime entry (deprecated compatibility):',",
"console.log(` - Legacy auth: ${LEGACY_CURSOR_COMMAND} auth`);",
"const LEGACY_CURSOR_COMMAND = 'ccs legacy cursor';"
]
},
{
"file": "src/config/migration-manager.ts",
"count": 9,
"calls": [],
"markers": [
"* Check if there are legacy profiles that haven't been migrated to config.yaml.",
"* Handles migration from legacy JSON config (v1) to unified YAML config (v2).",
"// Deterministic priority: explicit canonical profile wins over legacy alias rename.",
"`Profile \"${targetName}\" exists in both configs with different settings - keeping existing (${existingSettings}), skipping legacy ${sourceName} (${pathStr})`",
"`Renamed legacy API profile \"${sourceName}\" to \"${targetName}\" (ccs kimi API profile is now ccs km)`",
"console.log(infoBox('Migrated legacy profiles to config.yaml', 'SUCCESS'));",
"console.log(infoBox('Migration failed - using legacy config', 'WARNING'));"
]
},
{
"file": "src/cliproxy/config/__tests__/env-builder-provider-url.test.ts",
"count": 8,
"calls": [],
"markers": [
"ANTHROPIC_API_KEY: 'legacy-cursor-api-key',",
"it('imports legacy cursor settings into the dedicated provider path without reusing legacy transport auth', () => {",
"name: 'legacy-45',",
"name: 'legacy-codex',",
"name: 'legacy-iflow',",
"name: 'legacy',"
]
},
{
"file": "src/cliproxy/executor/__tests__/variant-port-edge-cases.test.js",
"count": 8,
"calls": [],
"markers": [
"* legacy migration, permission errors, and config corruption.",
"// Create legacy variant without port",
"assert.strictEqual(variants.legacy.port, undefined);",
"describe('Legacy Variant Migration', function () {",
"it('legacy variant does not block port allocation', function () {",
"legacy: {"
]
}
],
"explicitShimFiles": [
"src/cliproxy/__tests__/model-catalog-compat.test.ts",
"src/cliproxy/ai-providers/__tests__/codex-plan-compatibility.test.ts",
"src/cliproxy/ai-providers/__tests__/openai-compat-manager.test.js",
"src/cliproxy/ai-providers/openai-compat-manager.ts",
"src/cliproxy/types/__tests__/types-backward-compat.test.ts",
"src/utils/profile-compat.ts",
"src/web-server/services/compatible-cli-docs-registry.ts"
]
},
"maintainability": {
"typedErrors": {
"totalThrows": 455,
"typedThrows": 89,
"plainThrows": 306,
"otherThrows": 60,
"adoptionRatio": 0.1956,
"topSubdomainsByThrows": [
{
"subdomain": "web-server",
"count": 104,
"typed": 17,
"plain": 45
},
{
"subdomain": "commands",
"count": 38,
"typed": 6,
"plain": 30
},
{
"subdomain": "proxy",
"count": 38,
"typed": 0,
"plain": 34
},
{
"subdomain": "codex-auth",
"count": 35,
"typed": 4,
"plain": 27
},
{
"subdomain": "utils",
"count": 33,
"typed": 0,
"plain": 33
},
{
"subdomain": "targets",
"count": 27,
"typed": 9,
"plain": 16
},
{
"subdomain": "cursor",
"count": 23,
"typed": 4,
"plain": 17
},
{
"subdomain": "cliproxy/auth",
"count": 16,
"typed": 16,
"plain": 0
},
{
"subdomain": "cliproxy/accounts",
"count": 13,
"typed": 0,
"plain": 13
},
{
"subdomain": "auth",
"count": 12,
"typed": 12,
"plain": 0
}
]
},
"typedErrorAdoption": {
"subdomains": [
"cliproxy/quota",
"cliproxy/auth",
"web-server/routes",
"auth"
],
"numerator": 28,
"denominator": 30,
"ratio": 0.9333,
"targetRatio": 0.4
},
"loggerCoverage": {
"filesWithCreateLogger": 65,
"totalSourceFiles": 765,
"coverageRatio": 0.085,
"subdomainsWithZeroCreateLogger": [
"api",
"bin",
"channels",
"cliproxy",
"cliproxy/accounts",
"cliproxy/ai-providers",
"cliproxy/binary",
"cliproxy/config",
"cliproxy/management",
"cliproxy/sync",
"cliproxy/types",
"config",
"dispatcher",
"shared",
"types"
],
"topSubdomainsByFiles": [
{
"subdomain": "web-server",
"count": 112,
"withLogger": 10
},
{
"subdomain": "commands",
"count": 110,
"withLogger": 2
},
{
"subdomain": "utils",
"count": 90,
"withLogger": 1
},
{
"subdomain": "management",
"count": 35,
"withLogger": 1
},
{
"subdomain": "cliproxy/auth",
"count": 32,
"withLogger": 1
},
{
"subdomain": "cliproxy/quota",
"count": 31,
"withLogger": 5
},
{
"subdomain": "config",
"count": 27,
"withLogger": 0
},
{
"subdomain": "codex-auth",
"count": 24,
"withLogger": 9
},
{
"subdomain": "cursor",
"count": 24,
"withLogger": 2
},
{
"subdomain": "auth",
"count": 20,
"withLogger": 1
}
]
},
"hotpathConsoleErrors": {
"totalOccurrences": 590,
"exemptOccurrences": 326,
"hotpathOccurrences": 264,
"filesAffected": 81,
"topFiles": [
{
"file": "src/errors/error-handler.ts",
"count": 11
},
{
"file": "src/utils/prompt.ts",
"count": 11
},
{
"file": "src/utils/websearch/profile-hook-injector.ts",
"count": 10
},
{
"file": "src/cliproxy/accounts/account-safety-cross-lane.ts",
"count": 9
},
{
"file": "src/utils/hooks/image-analyzer-profile-hook-injector.ts",
"count": 9
},
{
"file": "src/utils/websearch/hook-installer.ts",
"count": 8
},
{
"file": "src/cliproxy/auth/token-manager.ts",
"count": 7
},
{
"file": "src/cliproxy/binary/downloader.ts",
"count": 7
},
{
"file": "src/cliproxy/executor/account-resolution.ts",
"count": 7
},
{
"file": "src/config/unified-config-loader.ts",
"count": 7
},
{
"file": "src/targets/claude-adapter.ts",
"count": 7
},
{
"file": "src/utils/shell-executor.ts",
"count": 7
},
{
"file": "src/utils/websearch/hook-config.ts",
"count": 7
},
{
"file": "src/targets/droid-detector.ts",
"count": 6
},
{
"file": "src/utils/hooks/image-analyzer-hook-installer.ts",
"count": 6
}
]
},
"largeFiles": {
"countOver400": 94,
"countOver600": 42,
"topOver400": [
{
"file": "src/web-server/usage/native-quota-collector.ts",
"loc": 1758
},
{
"file": "src/web-server/routes/cliproxy-auth-routes.ts",
"loc": 1531
},
{
"file": "src/cliproxy/auth/oauth-handler.ts",
"loc": 1510
},
{
"file": "src/cursor/cursor-executor.ts",
"loc": 1234
},
{
"file": "src/web-server/model-pricing.ts",
"loc": 1138
},
{
"file": "src/cliproxy/config/generator.ts",
"loc": 1109
},
{
"file": "src/cliproxy/auth/oauth-process.ts",
"loc": 1048
},
{
"file": "src/cliproxy/config/env-builder.ts",
"loc": 1045
},
{
"file": "src/web-server/routes/settings-routes.ts",
"loc": 1042
},
{
"file": "src/cliproxy/proxy/tool-sanitization-proxy.ts",
"loc": 1020
},
{
"file": "src/commands/cliproxy/variant-subcommand.ts",
"loc": 997
},
{
"file": "src/cliproxy/quota/quota-manager.ts",
"loc": 954
},
{
"file": "src/web-server/services/codex-dashboard-service.ts",
"loc": 940
},
{
"file": "src/glmt/glmt-proxy.ts",
"loc": 939
},
{
"file": "src/cliproxy/model-catalog.ts",
"loc": 884
}
]
}
}
}