Repository navigation
fix(platform-browser): escape newlines in Meta selector values - #71236
Open
rootvector2 wants to merge 1 commit into
Open
rootvector2 wants to merge 1 commit into
rootvector2 wants to merge 1 commit into
Conversation
`escapeSelectorValue` escaped only backslashes and double quotes, so a `name` or `property` value holding a newline ended the CSS string token early (CSS Syntax 3 4.3.5) and the derived `meta[...]` selector was rejected by `querySelector`. Write newline, carriage return and form feed as character escapes so the value stays inside the string.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PR Checklist
PR Type
What is the current behavior?
Issue Number: N/A
escapeSelectorValueescapes backslashes and double quotes to keep a value confined inside themeta[name="..."]selector thatparseSelectorderives. a newline cannot be confined that way: it terminates the string token (CSS Syntax 3 4.3.5), and carriage return and form feed are preprocessed into one (3.3). so anameorpropertyholding one of them produces a bad-string token, and the selector is invalid:the throw comes from
querySelectorinsidegetTags, so it escapesaddTag,updateTag,getTagandremoveTag. it is reachable wherever the tag name is taken from content rather than written literally, which is the normal shape for og/twitter tags driven by a cms or an api response.found while auditing the css-escaping helpers in
commonandplatform-browseragainst each other:escapeCssUrlinng_optimized_imagealready handles these characters and cites the same rule, andviewport_scrollerdefers toCSS.escape. this was the one that did not.What is the new behavior?
newline, carriage return and form feed are written as css character escapes (
\a,\d,\c), which represent the same code points inside the string, so the value round-trips and the tag is matched. values without those characters serialize byte for byte as before.Does this PR introduce a breaking change?
Other information
regression test added in
meta_spec.ts. it fails onmainin bothtest_web_chromiumandtest_web_firefoxwith theis not a valid selectorerror above and passes with this change. note the:testtarget would not have caught it, since domino accepts the invalid selector where browsers reject it.