chore: escape every value the views write as markup, and cut symbols on code points (closes #329)
The token screen's decimals and holder count, the ETH price, every address total and each balance row's USD value went into innerHTML unescaped, against the rule at the top of src/popup/views/helpers.js. They are escaped now. None could carry markup, but formatUsd() writes a value under a cent as "< $0.01". displaySymbol() counts a symbol in code points, not UTF-16 units, so the cut never leaves half of an emoji, which rendered as U+FFFD. explorerLink() was already removed on next. Model: opus-5-5
This commit is contained in:
@@ -91,6 +91,17 @@ describe("displaySymbol", () => {
|
||||
expect(displaySymbol(exact)).toBe(exact);
|
||||
});
|
||||
|
||||
// An emoji outside the Basic Multilingual Plane is two UTF-16 units.
|
||||
// Cutting between them leaves half of one, which renders as U+FFFD.
|
||||
test("counts an emoji as one character and never cuts one in half", () => {
|
||||
expect(displaySymbol("🚀".repeat(MAX_SYMBOL_LENGTH))).toBe(
|
||||
"🚀".repeat(MAX_SYMBOL_LENGTH),
|
||||
);
|
||||
expect(displaySymbol("🚀".repeat(20))).toBe(
|
||||
"🚀".repeat(MAX_SYMBOL_LENGTH - 1) + "…",
|
||||
);
|
||||
});
|
||||
|
||||
test("substitutes a placeholder for an absent symbol", () => {
|
||||
expect(displaySymbol("")).toBe(UNKNOWN_SYMBOL);
|
||||
expect(displaySymbol(null)).toBe(UNKNOWN_SYMBOL);
|
||||
|
||||
Reference in New Issue
Block a user