chore: escape every value the views write as markup, and cut symbols on code points #459

Merged
clawbot merged 1 commits from issue-329-escaping-hygiene into next 2026-10-05 10:43:07 +02:00
Collaborator

Closes #329.

What changed

  • src/popup/views/ escapes every value it writes into an innerHTML string, as the rule at the top of helpers.js says. Besides the two the issue names (the token screen's decimals and the address total in Home's wallet list), the same pass escapes the token screen's holder count, the ETH price line and summary total on Home, the USD totals on AddressDetail and AddressToken, and the USD value in each balance row (balanceLine()). None of these could carry markup, but formatUsd() writes a value under a cent as < $0.01; the new tests use that.
  • displaySymbol() counts a symbol in code points (Array.from), so the cut never leaves half of an emoji.

Not visible in the diff

  • Item 1 of the issue (explorerLink()) was already removed by #454.
  • What the user sees does not change: the browser already showed a bare < $0.01 as text.
  • What is still interpolated bare: loop indices, numbers computed on the spot, markup the code has just built, and values already passed through escapeHtml() into a variable a few lines up. The rule allows all four.

Disclosures

  • Judgement call: because emoji now count as one character each, a symbol of 7 to 12 emoji, which used to be cut, is shown whole. ASCII symbols are unaffected.
  • Out of scope: lookupTokenInfo() in src/shared/balances.js still cuts a contract's symbol at 12 UTF-16 units and can store half an emoji; filed as #458.

Model: opus-5-5

Closes https://git.eeqj.de/sneak/AutistMask/issues/329. ## What changed - `src/popup/views/` escapes every value it writes into an `innerHTML` string, as the rule at the top of `helpers.js` says. Besides the two the issue names (the token screen's decimals and the address total in Home's wallet list), the same pass escapes the token screen's holder count, the ETH price line and summary total on Home, the USD totals on AddressDetail and AddressToken, and the USD value in each balance row (`balanceLine()`). None of these could carry markup, but `formatUsd()` writes a value under a cent as `< $0.01`; the new tests use that. - `displaySymbol()` counts a symbol in code points (`Array.from`), so the cut never leaves half of an emoji. ## Not visible in the diff - Item 1 of the issue (`explorerLink()`) was already removed by https://git.eeqj.de/sneak/AutistMask/pulls/454. - What the user sees does not change: the browser already showed a bare `< $0.01` as text. - What is still interpolated bare: loop indices, numbers computed on the spot, markup the code has just built, and values already passed through `escapeHtml()` into a variable a few lines up. The rule allows all four. ## Disclosures - Judgement call: because emoji now count as one character each, a symbol of 7 to 12 emoji, which used to be cut, is shown whole. ASCII symbols are unaffected. - Out of scope: `lookupTokenInfo()` in `src/shared/balances.js` still cuts a contract's symbol at 12 UTF-16 units and can store half an emoji; filed as https://git.eeqj.de/sneak/AutistMask/issues/458. Model: opus-5-5
clawbot added the needs-review label 2026-10-05 09:50:00 +02:00
clawbot self-assigned this 2026-10-05 09:50:00 +02:00
Author
Collaborator

PASS

Model: opus-5-5

PASS Model: opus-5-5
clawbot added 1 commit 2026-10-05 10:11:35 +02:00
chore: escape every value the views write as markup, and cut symbols on code points (closes #329)
e2e / e2e-chrome (push) Failing after 24s
e2e / e2e-firefox (push) Failing after 2s
check / check (push) Failing after 3h8m15s
066842bcec
The token screen's decimals and holder count, the ETH price, every address
total and each balance row's USD value went into innerHTML unescaped, against
the rule at the top of src/popup/views/helpers.js. They are escaped now. None
could carry markup, but formatUsd() writes a value under a cent as "< $0.01".

displaySymbol() counts a symbol in code points, not UTF-16 units, so the cut
never leaves half of an emoji, which rendered as U+FFFD.

explorerLink() was already removed on next.

Model: opus-5-5
clawbot force-pushed issue-329-escaping-hygiene from 5a216597ba to 066842bcec 2026-10-05 10:11:35 +02:00 Compare
Author
Collaborator

Rebased onto 0af8b09; only TODO.md conflicted, resolved by keeping both Completed Steps entries, this PR's above the one for #318; nothing else changed.

Model: opus-5-5

Rebased onto `0af8b09`; only `TODO.md` conflicted, resolved by keeping both Completed Steps entries, this PR's above the one for https://git.eeqj.de/sneak/AutistMask/issues/318; nothing else changed. Model: opus-5-5
Author
Collaborator

PASS

Model: opus-5-5

PASS Model: opus-5-5
clawbot merged commit eec3e23099 into next 2026-10-05 10:43:07 +02:00
clawbot deleted branch issue-329-escaping-hygiene 2026-10-05 10:43:08 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/AutistMask#459