Commit 727c550003
727c5500035f58bac0d13ee1644a06c8f8bea770
parent: 1adb8b06ca
Unsigned
cmc <hello@cleberg.net> · 2026-07-20 16:03 UTC
Narrow esc() to primitives (S6551)
esc() accepted `unknown`, so an object passed by mistake would be
stringified as "[object Object]" and rendered straight into an evidence
table — a silent data-quality bug in exactly the place it matters least
to have one.
Narrowing the parameter to `string | number | null | undefined` makes
that a compile error instead of a runtime surprise. Every existing call
site already passes a primitive, so type checking is unchanged and the
bundle is byte-identical.
Escaping behaviour verified unchanged: the five HTML-significant
characters are still neutralised, and null/undefined still render empty.
Layout: unified · split
src/dashboard.ts
+4 −1
| @@ -47,7 +47,10 @@ export interface DashboardData { |
| 47 | 47 | lastPolledAt: string | null; |
| 48 | 48 | } |
| 49 | 49 | |
| 50 | | function esc(value: unknown): string { |
| 50 | // Deliberately narrower than `unknown`: an object reaching here would render |
| 51 | // as "[object Object]" in an evidence table, which is worse than failing. |
| 52 | // Keeping the parameter to primitives makes that a compile error instead. |
| 53 | function esc(value: string | number | null | undefined): string { |
| 51 | 54 | return String(value ?? "").replace(/[&<>"']/g, (c) => { |
| 52 | 55 | switch (c) { |
| 53 | 56 | case "&": return "&"; |