fix(security): handle non-string inputs in escapeHtml to prevent crashes
- Update `escapeHtml` to explicitly coerce input to string - Handle null/undefined values safely - Add unit tests for non-string input types (numbers, booleans, objects)
This commit is contained in:
+3
-3
@@ -165,9 +165,9 @@ export function createDebugLogger(
|
||||
* @param str - The string to escape
|
||||
* @returns Escaped string
|
||||
*/
|
||||
export function escapeHtml(str: string): string {
|
||||
if (!str) return str;
|
||||
return str
|
||||
export function escapeHtml(str: unknown): string {
|
||||
if (str === null || str === undefined) return '';
|
||||
return String(str)
|
||||
.replace(/&/g, "&")
|
||||
.replace(/</g, "<")
|
||||
.replace(/>/g, ">")
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
import { describe, it, expect } from 'vitest';
|
||||
import { formatValue } from '../../src/info-panel/ValueFormatter';
|
||||
import { escapeHtml } from '../../src/shared/utils';
|
||||
|
||||
describe('Security', () => {
|
||||
describe('formatValue', () => {
|
||||
@@ -51,4 +52,19 @@ describe('Security', () => {
|
||||
expect(renderedValue).toContain('<script>');
|
||||
});
|
||||
});
|
||||
|
||||
describe('Robustness', () => {
|
||||
it('should safely handle non-string inputs in escapeHtml', () => {
|
||||
expect(escapeHtml(123)).toBe('123');
|
||||
expect(escapeHtml(0)).toBe('0');
|
||||
expect(escapeHtml(true)).toBe('true');
|
||||
expect(escapeHtml(false)).toBe('false');
|
||||
expect(escapeHtml(null)).toBe('');
|
||||
expect(escapeHtml(undefined)).toBe('');
|
||||
|
||||
// Object with toString
|
||||
const obj = { toString: () => '<script>' };
|
||||
expect(escapeHtml(obj)).toBe('<script>');
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user