Chore: Fixes cleanNeedle regex to be more specific (#61967)

* Chore: Fixes code sec warning for frontend regex

* Update text.ts

* Update text.ts
This commit is contained in:
Torkel Ödegaard
2023-01-26 09:08:15 +01:00
committed by GitHub
parent 6a93c77082
commit 8e3d22ca7a
+5 -1
View File
@@ -24,7 +24,7 @@ export function findHighlightChunksInText({
} }
const cleanNeedle = (needle: string): string => { const cleanNeedle = (needle: string): string => {
return needle.replace(/[[{(][\w,.-?:*+]+$/, ''); return needle.replace(/[[{(][\w,.\/:;<=>?:*+]+$/, '');
}; };
/** /**
@@ -35,14 +35,17 @@ export function findMatchesInText(haystack: string, needle: string): TextMatch[]
if (!haystack || !needle) { if (!haystack || !needle) {
return []; return [];
} }
const matches: TextMatch[] = []; const matches: TextMatch[] = [];
const { cleaned, flags } = parseFlags(cleanNeedle(needle)); const { cleaned, flags } = parseFlags(cleanNeedle(needle));
let regexp: RegExp; let regexp: RegExp;
try { try {
regexp = new RegExp(`(?:${cleaned})`, flags); regexp = new RegExp(`(?:${cleaned})`, flags);
} catch (error) { } catch (error) {
return matches; return matches;
} }
haystack.replace(regexp, (substring, ...rest) => { haystack.replace(regexp, (substring, ...rest) => {
if (substring) { if (substring) {
const offset = rest[rest.length - 2]; const offset = rest[rest.length - 2];
@@ -55,6 +58,7 @@ export function findMatchesInText(haystack: string, needle: string): TextMatch[]
} }
return ''; return '';
}); });
return matches; return matches;
} }