fix(security): handle non-string inputs in escapeHtml to prevent crashes

- Update `escapeHtml` to explicitly coerce input to string
- Handle null/undefined values safely
- Add unit tests for non-string input types (numbers, booleans, objects)
This commit is contained in:
google-labs-jules[bot]
2026-01-14 05:56:33 +00:00
parent 4cf3e9f50b
commit 5e5c49a99c
2 changed files with 19 additions and 3 deletions
+3 -3
View File
@@ -165,9 +165,9 @@ export function createDebugLogger(
* @param str - The string to escape
* @returns Escaped string
*/
export function escapeHtml(str: string): string {
if (!str) return str;
return str
export function escapeHtml(str: unknown): string {
if (str === null || str === undefined) return '';
return String(str)
.replace(/&/g, "&")
.replace(/</g, "&lt;")
.replace(/>/g, "&gt;")
+16
View File
@@ -1,5 +1,6 @@
import { describe, it, expect } from 'vitest';
import { formatValue } from '../../src/info-panel/ValueFormatter';
import { escapeHtml } from '../../src/shared/utils';
describe('Security', () => {
describe('formatValue', () => {
@@ -51,4 +52,19 @@ describe('Security', () => {
expect(renderedValue).toContain('&lt;script&gt;');
});
});
describe('Robustness', () => {
it('should safely handle non-string inputs in escapeHtml', () => {
expect(escapeHtml(123)).toBe('123');
expect(escapeHtml(0)).toBe('0');
expect(escapeHtml(true)).toBe('true');
expect(escapeHtml(false)).toBe('false');
expect(escapeHtml(null)).toBe('');
expect(escapeHtml(undefined)).toBe('');
// Object with toString
const obj = { toString: () => '<script>' };
expect(escapeHtml(obj)).toBe('&lt;script&gt;');
});
});
});