Skip to content

fix(ui): inert HTML parsing in stripHtml/isEmptyHtml (ui 0.7.2) - #21

Merged
rrolf merged 1 commit into
mainfrom
fix/inert-html-parsing
Oct 7, 2026
Merged

rrolf merged 1 commit into
mainfrom
fix/inert-html-parsing

Conversation

@rrolf

@rrolf rrolf commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Closes #20

  • stripHtml and isEmptyHtml used to parse via innerHTML on an element of the live document. The browser loads images there and runs inline handlers, so <img src=x onerror=…> executed even on a detached element. They now parse in an inert DOMParser document, where nothing runs or loads. isEmptyHtml detects images through the parsed body instead of a regex.
  • Corrected the doc comment in html.ts, which claimed that nothing is executed.
  • Version 0.7.2, CHANGELOG entry (no migration needed). The released 0.7.1 notes are moved from [Unreleased] into their own section.

Verified in Ausleihbar with a local tgz, calling the functions in the browser:

Input Result
<img onerror> payload handler does not run
stripHtml('<p>Hallo <b>Welt</b> &amp; mehr</p>…') "Hallo Welt & mehr"
isEmptyHtml('<p></p>'), isEmptyHtml('<p><br></p>'), isEmptyHtml(null) true
isEmptyHtml('<p>x</p>'), isEmptyHtml('<p><img …></p>') false

tsc and build clean. The UI package has no test setup.

🤖 Generated with Claude Code

…tyHtml (#20)

innerHTML on an element of the live document loads images and runs inline
handlers (<img onerror>), even when detached. DOMParser documents execute
and fetch nothing. Behaviour otherwise unchanged. Bump ui to 0.7.2; move the
released 0.7.1 notes out of [Unreleased].

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@rrolf
rrolf merged commit 327d481 into main Oct 7, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ui: stripHtml/isEmptyHtml parsen über innerHTML im Live-Dokument (Event-Handler können ausgeführt werden)

1 participant