Sanitize resultsdb summary html a bit

This will prevent error messages with html tags in them from
accidentally formatting the error message

Bug: none
Change-Id: Iea6f1e84017dfc4451fe6aad331abf2d1a1c2133
Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/4660497
Reviewed-by: Liviu Rau <liviurau@google.com>
Commit-Queue: Liviu Rau <liviurau@google.com>
Reviewed-by: Simon Zünd <szuend@chromium.org>
Auto-Submit: Philip Pfaffe <pfaffe@chromium.org>
This commit is contained in:
Philip Pfaffe
2023-07-07 12:22:51 +00:00
committed by Devtools-frontend LUCI CQ
parent 408ed8ac40
commit 117012423f
+12 -4
View File
@@ -13,7 +13,15 @@ const {
EVENT_TEST_PENDING,
} = Mocha.Runner.constants;
function getErrorMessage(error: Error|unknown) {
function sanitize(message: string): string {
return message.replaceAll('&', '&amp;')
.replaceAll('<', '&lt;')
.replaceAll('>', '&gt;')
.replaceAll('"', '&quot;')
.replaceAll('\'', '&#39;');
}
function getErrorMessage(error: Error|unknown): string {
if (error instanceof Error) {
if (error.cause) {
// TypeScript types error.cause as {}, which doesn't allow us to access
@@ -21,11 +29,11 @@ function getErrorMessage(error: Error|unknown) {
// to read the `message` property.
const cause = error.cause as {message?: string};
const causeMessage = cause.message || '';
return `${error.message}\n${causeMessage}`;
return sanitize(`${error.message}\n${causeMessage}`);
}
return error.stack;
return sanitize(error.stack ?? error.message);
}
return `${error}`;
return sanitize(`${error}`);
}
class ResultsDbReporter extends Mocha.reporters.Spec {