Repository navigation
fix: escape context labels in html report inline script block - #2224
Merged
Merged
Conversation
Member
|
Thanks! |
Contributor
Author
|
Thanks for merging! This is my first open-source contribution. I'd love any feedback to help me improve. |
Member
|
You did great. I really appreciate that you included a test and a changelog entry. Most people include tests, but not the changelog. I hope I gave you the right attribution. |
Member
|
This is now released as part of coverage 7.15.1. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
With
coverage html --show-contexts, each file page carries its context labels as JSON inside an inline<script>element.switch_contexttakes any string (pytest-cov feeds it test node ids, which can hold arbitrary characters through parametrization), so a label like</script>...closes the script element early and the browser parses whatever follows as live markup in the published report.Escape the HTML-significant characters in that JSON as
\uXXXXright where it's built. The escapes are still valid JSON, socoverage_html.jsreads the same label values back, and keeping the escaping at the serialization point covers every label without each context producer having to sanitize its own strings.