chore: escape every value the views write as markup, and cut symbols on code points (closes #329)
The token screen's decimals and holder count, the ETH price, every address total and each balance row's USD value went into innerHTML unescaped, against the rule at the top of src/popup/views/helpers.js. They are escaped now. None could carry markup, but formatUsd() writes a value under a cent as "< $0.01". displaySymbol() counts a symbol in code points, not UTF-16 units, so the cut never leaves half of an emoji, which rendered as U+FFFD. explorerLink() was already removed on next. Model: opus-5-5
This commit was merged in pull request #459.
This commit is contained in:
@@ -194,6 +194,14 @@ describe("the wallet list on Home", () => {
|
||||
clearPrices();
|
||||
expect(walletListTotal(FULLY_PRICED)).toBe(" ");
|
||||
});
|
||||
|
||||
// A total under a cent is written "< $0.01", and the "<" is escaped
|
||||
// here as the removal warning escapes it.
|
||||
test("a total under a cent is escaped, as on the removal warning", () => {
|
||||
const tiny = { ...EMPTY, balance: "0.000001" };
|
||||
expect(walletListTotal(tiny)).toBe("Total: < $0.01");
|
||||
expect(removalWarningTotal(tiny)).toBe("Total: < $0.01");
|
||||
});
|
||||
});
|
||||
|
||||
describe("the balance warning on the address-removal confirmation", () => {
|
||||
|
||||
@@ -66,4 +66,11 @@ describe("balanceLine", () => {
|
||||
expect(html).toContain("<span>1.5000</span>");
|
||||
expect(html).toContain('data-token="0xabc"');
|
||||
});
|
||||
|
||||
// formatUsd() writes a value under a cent as "< $0.01".
|
||||
test("escapes the USD value along with the symbol", () => {
|
||||
const html = balanceLine("USDC", 0.001, 1, null);
|
||||
expect(html).toContain("< $0.01");
|
||||
expect(html).not.toContain("< $0.01");
|
||||
});
|
||||
});
|
||||
|
||||
@@ -91,6 +91,17 @@ describe("displaySymbol", () => {
|
||||
expect(displaySymbol(exact)).toBe(exact);
|
||||
});
|
||||
|
||||
// An emoji outside the Basic Multilingual Plane is two UTF-16 units.
|
||||
// Cutting between them leaves half of one, which renders as U+FFFD.
|
||||
test("counts an emoji as one character and never cuts one in half", () => {
|
||||
expect(displaySymbol("🚀".repeat(MAX_SYMBOL_LENGTH))).toBe(
|
||||
"🚀".repeat(MAX_SYMBOL_LENGTH),
|
||||
);
|
||||
expect(displaySymbol("🚀".repeat(20))).toBe(
|
||||
"🚀".repeat(MAX_SYMBOL_LENGTH - 1) + "…",
|
||||
);
|
||||
});
|
||||
|
||||
test("substitutes a placeholder for an absent symbol", () => {
|
||||
expect(displaySymbol("")).toBe(UNKNOWN_SYMBOL);
|
||||
expect(displaySymbol(null)).toBe(UNKNOWN_SYMBOL);
|
||||
|
||||
Reference in New Issue
Block a user