fix(performance): strip inert HTML to a fixpoint

Repeat the comment and inline-body removal until nothing changes, so the
pieces around a removed comment cannot assemble into a tag that a single
pass would then count (CodeQL: incomplete multi-character sanitization).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
4grayandClaude Fable 5.1 committed 2026-09-26 11:12:50 +02:00
1 parent be58eacb20
commit dfe884360d
2 files changed
+18 -2

No files matched your search

+11 -1
View File
@@ -66,7 +66,17 @@ function classify(tag, attributes) {
* inline script element is still seen.
*/
export function stripInertHtml(html) {
return html.replace(HTML_COMMENT, '').replace(INLINE_ELEMENT_BODY, '$1$3');
// Repeat until nothing changes: a single pass can expose a new comment or
// element body assembled from the pieces around a removed one.
let previous;
let stripped = html;
do {
previous = stripped;
stripped = stripped
.replace(HTML_COMMENT, '')
.replace(INLINE_ELEMENT_BODY, '$1$3');
} while (stripped !== previous);
return stripped;
}
/**
@@ -132,7 +132,13 @@ test('ignores commented-out tags and tag-like text inside inline scripts and sty
extractInitialResources(html).map((resource) => resource.url),
['assets/app-config.js', 'main.js']
);
assert.equal(stripInertHtml('<script>1 < 2</script>'), '<script></script>');
assert.equal(stripInertHtml('<script>1 < 2</script>'), '<script></script>'); // Pieces around a removed comment must not assemble into a live tag.
assert.deepEqual(
extractInitialResources(
'<!<!-- a -->-- <script src="x.js"></script> -->'
),
[]
);
});
test('counts a file once per distinct request URL', async () => {