chore: escape every value the views write as markup, and cut symbols on code points (closes #329)
The token screen's decimals and holder count, the ETH price, every address total and each balance row's USD value went into innerHTML unescaped, against the rule at the top of src/popup/views/helpers.js. They are escaped now. None could carry markup, but formatUsd() writes a value under a cent as "< $0.01". displaySymbol() counts a symbol in code points, not UTF-16 units, so the cut never leaves half of an emoji, which rendered as U+FFFD. explorerLink() was already removed on next. Model: opus-5-5
This commit was merged in pull request #459.
This commit is contained in:
@@ -45,6 +45,16 @@ but the review is broader than any of them.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-05: Escaping in the popup's views follows its own rule with no
|
||||
exceptions ([#329](https://git.eeqj.de/sneak/AutistMask/issues/329)). The
|
||||
decimals and holder count on a token's screen, and every USD figure (the ETH
|
||||
price, each total and each balance row's value), went into `innerHTML`
|
||||
unescaped; they are escaped now. None could carry markup, but `formatUsd()`
|
||||
writes a value under a cent as `< $0.01`. `displaySymbol()` counts a symbol in
|
||||
code points rather than UTF-16 units, so a cut never splits an emoji into a
|
||||
half that renders as U+FFFD. `explorerLink()`, also named in the issue, was
|
||||
already removed by [#168](https://git.eeqj.de/sneak/AutistMask/issues/168).
|
||||
|
||||
- 2026-10-05: A Chrome end-to-end test that fails no longer takes later tests
|
||||
down with it ([#318](https://git.eeqj.de/sneak/AutistMask/issues/318)). Each
|
||||
test that turns a fixture switch on for itself alone (a held or failing gas
|
||||
|
||||
Reference in New Issue
Block a user