Skip to content

fix: escape user provided HTML attribute values - #306

Merged
stephancill merged 1 commit into
devfrom
fix/escape-user-provided-html-attribute-values
Apr 12, 2024
Merged

fix: escape user provided HTML attribute values#306
stephancill merged 1 commit into
devfrom
fix/escape-user-provided-html-attribute-values

Conversation

@michalkvasnicak

@michalkvasnicak michalkvasnicak commented Apr 11, 2024

Copy link
Copy Markdown
Collaborator

Change Summary

This PR properly escapes user provided HTML attribute values. This for example fixes an issue when state value contains double quotes or single quotes, etc. All proper HTML parsers should be able to decode the values properly.

https://linear.app/modprotocol/issue/FRA-176/bug-report-with-deserializing-state

Merge Checklist

  • PR has a Changeset
  • PR includes documentation if necessary
  • PR updates the boilerplates if necessary

@vercel

vercel Bot commented Apr 11, 2024

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
frames-js ✅ Ready (Inspect) Visit Preview 💬 Add feedback Apr 11, 2024 2:09pm
framesjs-debugger ✅ Ready (Inspect) Visit Preview 💬 Add feedback Apr 11, 2024 2:09pm

@stephancill
stephancill merged commit 5061f8b into dev Apr 12, 2024
@stephancill
stephancill deleted the fix/escape-user-provided-html-attribute-values branch April 12, 2024 08:34
stephancill added a commit that referenced this pull request Apr 12, 2024
* chore: move starters to templates (#300)

* chore: move utils starter completely to templates

* fix: utils starter is esm module, fix config

* fix: use also FARCASTER_DEVELOPER_FID env variable in debugger bin

* chore: remove unused command

* chore: move starter to templates

* chore: changeset

* chore: update docs

* chore: changeset

* fix: typo

* chore: add readme

* feat: image rendering worker (#296)

* feat: images worker middleware

* feat: signatures, createImagesWorker

* fix: types

* fix: docs typo

* fix: docs dead links

* fix: docs typo

* fix: index exports

* fix: escape user provided HTML attribute values (#306)

* fix: next.js generateMetadata example code (#305)

---------

Co-authored-by: Michal Kvasničák <michal.kvasnicak@gmail.com>
Co-authored-by: Jereld Lim <jereldlimjy@hotmail.com>
stephancill added a commit that referenced this pull request Apr 15, 2024
* chore: move starters to templates (#300)

* chore: move utils starter completely to templates

* fix: utils starter is esm module, fix config

* fix: use also FARCASTER_DEVELOPER_FID env variable in debugger bin

* chore: remove unused command

* chore: move starter to templates

* chore: changeset

* chore: update docs

* chore: changeset

* fix: typo

* chore: add readme

* feat: image rendering worker (#296)

* feat: images worker middleware

* feat: signatures, createImagesWorker

* fix: types

* fix: docs typo

* fix: docs dead links

* fix: docs typo

* fix: index exports

* fix: escape user provided HTML attribute values (#306)

* fix: next.js generateMetadata example code (#305)

* fix: cloudflare worker template start command (#308)

* fix: lock next version, move react do production dependencies (#309)

* feat: add frames.js:version meta tag to frame response (#302)

* feat: add frames.js:version meta tag to frame response

* chore: update snapshots

* fix: add og:image to required properties, matching spec

* fix: type checking

* fix: rebuild frames.js after version bump

* feat: add a test to check parsing of html escaped characters in getFrame

* fix: publish-packages script

---------

Co-authored-by: Michal Kvasničák <michal.kvasnicak@gmail.com>
Co-authored-by: Jereld Lim <jereldlimjy@hotmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants