mirror of
https://github.com/priyanshujain/sanderling.git
synced 2026-10-04 20:17:09 +00:00
fix(chrome): validate attribute name in unknown-prefix branch
A selector like `foo]:has(*),body[x:value` previously produced [foo]:has(*),body[x="..."], a syntactically valid CSS selector that escaped the attribute match and selected `body`. Reject anything that isn't a plain HTML attribute name.
This commit is contained in:
1 parent
8c7470a1a6
commit
a69bac7abd
2 files changed
+24
No files matched your search
@@ -64,6 +64,21 @@ func TestTranslateStringSelector_RejectsMissingPrefix(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestTranslateStringSelector_RejectsUnsafePrefix(t *testing.T) {
|
||||
cases := []string{
|
||||
`foo]:has(*),body[x:value`,
|
||||
`x y:value`,
|
||||
`x"y:value`,
|
||||
`*:value`,
|
||||
`(:value`,
|
||||
}
|
||||
for _, selector := range cases {
|
||||
if _, _, err := TranslateStringSelector(selector); err == nil {
|
||||
t.Errorf("%q: expected error for unsafe prefix", selector)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestCSSEscape_ControlCharactersAndNUL(t *testing.T) {
|
||||
cases := []struct {
|
||||
name string
|
||||
|
||||
Reference in new issue
Block a user