Commit 727c550003

727c5500035f58bac0d13ee1644a06c8f8bea770

parent: 1adb8b06ca

Unsigned

cmc <hello@cleberg.net> · 2026-07-20 16:03 UTC

Narrow esc() to primitives (S6551)

esc() accepted `unknown`, so an object passed by mistake would be
stringified as "[object Object]" and rendered straight into an evidence
table — a silent data-quality bug in exactly the place it matters least
to have one.

Narrowing the parameter to `string | number | null | undefined` makes
that a compile error instead of a runtime surprise. Every existing call
site already passes a primitive, so type checking is unchanged and the
bundle is byte-identical.

Escaping behaviour verified unchanged: the five HTML-significant
characters are still neutralised, and null/undefined still render empty.

Layout: unified · split

src/dashboard.ts +4 −1
@@ -47,7 +47,10 @@ export interface DashboardData {
4747 lastPolledAt: string | null;
4848}
4949
50function esc(value: unknown): string {
50// Deliberately narrower than `unknown`: an object reaching here would render
51// as "[object Object]" in an evidence table, which is worse than failing.
52// Keeping the parameter to primitives makes that a compile error instead.
53function esc(value: string | number | null | undefined): string {
5154 return String(value ?? "").replace(/[&<>"']/g, (c) => {
5255 switch (c) {
5356 case "&": return "&amp;";