Skip to content

fix: escape context labels in html report inline script block - #2224

Merged
nedbat merged 3 commits into
coveragepy:mainfrom
rajath201:html-context-script-escape
Jul 11, 2026
Merged

nedbat merged 3 commits into
coveragepy:mainfrom
rajath201:html-context-script-escape

Conversation

@rajath201

Copy link
Copy Markdown
Contributor

With coverage html --show-contexts, each file page carries its context labels as JSON inside an inline <script> element. switch_context takes any string (pytest-cov feeds it test node ids, which can hold arbitrary characters through parametrization), so a label like </script>... closes the script element early and the browser parses whatever follows as live markup in the published report.

Escape the HTML-significant characters in that JSON as \uXXXX right where it's built. The escapes are still valid JSON, so coverage_html.js reads the same label values back, and keeping the escaping at the serialization point covers every label without each context producer having to sanitize its own strings.

@nedbat
nedbat merged commit dd80635 into coveragepy:main Jul 11, 2026
42 checks passed
@nedbat

nedbat commented Jul 11, 2026

Copy link
Copy Markdown
Member

Thanks!

@rajath201

Copy link
Copy Markdown
Contributor Author

Thanks for merging! This is my first open-source contribution. I'd love any feedback to help me improve.

@nedbat

nedbat commented Jul 11, 2026

Copy link
Copy Markdown
Member

You did great. I really appreciate that you included a test and a changelog entry. Most people include tests, but not the changelog. I hope I gave you the right attribution.

@nedbat

nedbat commented Jul 12, 2026

Copy link
Copy Markdown
Member

This is now released as part of coverage 7.15.1.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants