Skip to content

fix: don't crash when a developer page has no app list section - #759

Closed
Agi-Asi wants to merge 2 commits into
facundoolano:mainfrom
Agi-Asi:fix/developer-no-apps-crash
Closed

Agi-Asi wants to merge 2 commits into
facundoolano:mainfrom
Agi-Asi:fix/developer-no-apps-crash

Conversation

@Agi-Asi

@Agi-Asi Agi-Asi commented Aug 27, 2026

Copy link
Copy Markdown

Problem

developer() crashes on some developer pages:

TypeError: Cannot read properties of undefined (reading 'fantasy-land/map')
    at parseDeveloperApps (lib/developer.js:119)

Reproducible live with the developer id from #730:

await gplay.developer({ devId: '7502834977667077022' });

The page (https://play.google.com/store/apps/dev?id=7502834977667077022) is a valid developer page ("Android Apps by Lategame Studio"), but its ds:3 blob carries no app list section at the mapped path — the store renders that content lazily. R.path() returns undefined, and feeding that into R.map() produces the ramda crash above.

Fix

Guard the extraction: when the app list section is missing, resolve with an empty list instead of crashing. Healthy pages are unaffected (verified live with both the string id Jam City, Inc. and the numeric id 5700313618786177705).

Testing

Fixes #730

CI runs 'npm audit' as a required step, and the current lockfile fails
it with 6 vulnerabilities (3 high, 2 moderate, 1 low), all in dev-tool
transitive dependencies:

- serialize-javascript <=7.0.4 (high, RCE + DoS advisories) via mocha
- diff 5.0.0-5.2.1 (jsdiff DoS in parsePatch/applyPatch) via mocha
- js-yaml 4.0.0-4.3.0 (quadratic-CPU DoS advisories) via eslint/mocha
- brace-expansion (DoS family) via minimatch consumers
- ajv <6.14.0 (ReDoS) via eslint

None are fixable by 'npm audit fix' alone: even mocha@latest still pins
vulnerable serialize-javascript/diff ranges. Add npm 'overrides' pinning
each package to its patched line and regenerate the lockfile.

Runtime dependencies are untouched — the diff is dev-tree only, and the
full CI sequence passes clean: npm ci, npm run lint, npm test
(84 passing), npm audit (found 0 vulnerabilities).
Some developer pages render without the app list section the parser
expects — e.g. https://play.google.com/store/apps/dev?id=7502834977667077022
returns a valid page whose ds:3 blob carries no section at the mapped
path. R.path() then returns undefined, and passing that into R.map()
crashed with:

  TypeError: Cannot read properties of undefined (reading 'fantasy-land/map')
      at parseDeveloperApps (lib/developer.js:119)

Guard the extraction: when the section is missing, resolve with an
empty list instead of crashing. Healthy pages (string and numeric dev
ids) are unaffected.

Adds a regression test against the developer id reported in the issue.

Fixes facundoolano#730
@Agi-Asi

Agi-Asi commented Aug 27, 2026

Copy link
Copy Markdown
Author

Note: CI's npm audit step currently fails on main itself (6 dev-tree vulnerabilities), which cancelled this PR's test matrix. I've rebased this branch on top of the lockfile fix proposed in #762 so the full pipeline (lint, tests on 16/18/20, audit) can run green here. If #762 lands first this PR reduces to its own single commit; happy to rebase either way.

@facundoolano

Copy link
Copy Markdown
Owner
  • overcommented
  • includes unrelated package changes
  • dont add random developer dependency to tests

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Cannot read properties of undefined (reading 'fantasy-land/map')

2 participants