fix(.cursor/hooks): route block-no-verify through local hook to fix message-body false positives (#2107) - #2177
Conversation
…essage-body false positives (affaan-m#2107) Cursor hooks still called `npx block-no-verify@1.1.2`, the broken external package whose matcher over-matches: it blocks legitimate `git commit` whenever `--no-verify` (or `no-verify`) appears anywhere in the command string, including inside the commit message body. The Claude Code surface already routes through the in-repo `scripts/hooks/block-no-verify.js`, which performs flag-position-aware tokenisation and passes 25 regression tests covering every false-positive case from affaan-m#2107. Add a thin Cursor wrapper (`before-shell-execution-block-no-verify.js`) that reads Cursor stdin, transforms to the Claude Code `tool_input.command` shape, delegates to the local hook's exported `run()`, and forwards exit code and stderr. Update `.cursor/hooks.json` to call the wrapper instead of the npx package. New 14-case test file pins the false-positive cases from the issue plus the still-blocked real bypass attempts. Fixes affaan-m#2107
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (3)
📝 WalkthroughWalkthroughThis PR replaces the npm-based ChangesHook Wiring and Wrapper Implementation
Hook Wrapper Validation Tests
🎯 2 (Simple) | ⏱️ ~10 minutes
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Warning There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure. 🔧 ESLint
ESLint install failed. For unrecoverable errors, disable the tool in CodeRabbit configuration. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
ECC bundle files are already tracked in this repository. Skipping generation of another bundle PR. |
|
@coderabbitai review |
✅ Action performedReview finished.
|
…essage-body false positives (affaan-m#2107) (affaan-m#2177) Cursor hooks still called `npx block-no-verify@1.1.2`, the broken external package whose matcher over-matches: it blocks legitimate `git commit` whenever `--no-verify` (or `no-verify`) appears anywhere in the command string, including inside the commit message body. The Claude Code surface already routes through the in-repo `scripts/hooks/block-no-verify.js`, which performs flag-position-aware tokenisation and passes 25 regression tests covering every false-positive case from affaan-m#2107. Add a thin Cursor wrapper (`before-shell-execution-block-no-verify.js`) that reads Cursor stdin, transforms to the Claude Code `tool_input.command` shape, delegates to the local hook's exported `run()`, and forwards exit code and stderr. Update `.cursor/hooks.json` to call the wrapper instead of the npx package. New 14-case test file pins the false-positive cases from the issue plus the still-blocked real bypass attempts. Fixes affaan-m#2107
Summary
npx block-no-verify@1.1.2, theexternal package whose matcher over-matches: it blocks legitimate
git commitwhenever the literal string--no-verify(orno-verify)appears anywhere in the command — including inside the commit message
body. See #2107 for the
reproduction.
hooks/hooks.json) already routes throughthe local
scripts/hooks/block-no-verify.js, which usesflag-position-aware tokenisation (
-m/-F/-am "..."/-tnetc.)and already passes 25 regression tests covering every false-positive
case described in block-no-verify over-matches: blocks commits when the flag appears in the commit message body #2107. Cursor users were missing out.
.cursor/hooks/before-shell-execution-block-no-verify.js,that reads Cursor stdin, transforms to the Claude Code
tool_input.commandshape, delegates to the local hook's exportedrun(), and forwards exit code and stderr. Update.cursor/hooks.jsonto call the wrapper instead of the npx package.
ECC_HOOK_PROFILEandECC_DISABLED_HOOKS=pre:bash:block-no-verifyruntime gating viaadapter.hookEnabled, matching the rest of the Cursor hook surface.Verification
node tests/hooks/cursor-block-no-verify.test.js— 14/14 pass (newfile; pins each false-positive case from block-no-verify over-matches: blocks commits when the flag appears in the commit message body #2107 plus the still-blocked
real bypass attempts and the disable-via-env path).
node tests/hooks/block-no-verify.test.js— 25/25 pass (existinglocal-hook tests stay green).
node tests/run-all.js— 2633/2633 pass.node scripts/ci/validate-no-personal-paths.js— clean.node scripts/ci/check-unicode-safety.js— clean.node scripts/ci/validate-hooks.js— 28 hook matchers validated.npx eslint tests/hooks/cursor-block-no-verify.test.js— clean(
.cursor/**is intentionally ignored byeslint.config.js).Fixes #2107
Summary by cubic
Route Cursor’s
block-no-verifyhook through the local, flag-aware implementation to stop false blocks when--no-verifyappears in commit messages, while still blocking real bypass attempts. Fixes #2107.npx block-no-verify@1.1.2withnode .cursor/hooks/before-shell-execution-block-no-verify.js, which delegates toscripts/hooks/block-no-verify.jsfor position-aware parsing and consistent behavior with Claude Code.tests/hooks/cursor-block-no-verify.test.js(14 cases) to pin false-positive regressions and blocking paths; wrapper respectsECC_HOOK_PROFILEandECC_DISABLED_HOOKS.Written for commit 484b6d5. Summary will update on new commits.
Summary by CodeRabbit
Tests
Chores