mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-08 17:06:15 -08:00
fix(performance): strip inert HTML to a fixpoint
Repeat the comment and inline-body removal until nothing changes, so the pieces around a removed comment cannot assemble into a tag that a single pass would then count (CodeQL: incomplete multi-character sanitization). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
1 parent
be58eacb20
commit
dfe884360d
2 files changed
+18
-2
No files matched your search
@@ -66,7 +66,17 @@ function classify(tag, attributes) {
|
||||
* inline script element is still seen.
|
||||
*/
|
||||
export function stripInertHtml(html) {
|
||||
return html.replace(HTML_COMMENT, '').replace(INLINE_ELEMENT_BODY, '$1$3');
|
||||
// Repeat until nothing changes: a single pass can expose a new comment or
|
||||
// element body assembled from the pieces around a removed one.
|
||||
let previous;
|
||||
let stripped = html;
|
||||
do {
|
||||
previous = stripped;
|
||||
stripped = stripped
|
||||
.replace(HTML_COMMENT, '')
|
||||
.replace(INLINE_ELEMENT_BODY, '$1$3');
|
||||
} while (stripped !== previous);
|
||||
return stripped;
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
@@ -132,7 +132,13 @@ test('ignores commented-out tags and tag-like text inside inline scripts and sty
|
||||
extractInitialResources(html).map((resource) => resource.url),
|
||||
['assets/app-config.js', 'main.js']
|
||||
);
|
||||
assert.equal(stripInertHtml('<script>1 < 2</script>'), '<script></script>');
|
||||
assert.equal(stripInertHtml('<script>1 < 2</script>'), '<script></script>'); // Pieces around a removed comment must not assemble into a live tag.
|
||||
assert.deepEqual(
|
||||
extractInitialResources(
|
||||
'<!<!-- a -->-- <script src="x.js"></script> -->'
|
||||
),
|
||||
[]
|
||||
);
|
||||
});
|
||||
|
||||
test('counts a file once per distinct request URL', async () => {
|
||||
|
||||
Reference in new issue
Block a user