Automatic update from web-platform-tests Fix ScanEscapedAttrValue https://crrev.com/c/6491750 introduced a change, which deleted a crucial line from ScanEscapedAttrValue(), which moved the `pos_` variable past the quote character. The effect of that is that the parser now treats the opening quote character as the closing quote character and misparses the value of an attribute, which can lead to spurious attributes. See https://crbug.com/435995566 for details. This CL adds this one line back and also adds a regression test to ensure that this bug won't be re-introduced in the future. Fixed: 435995566 Change-Id: I69d932d03f44652ccebb5362929bfe688340179e Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/6814951 Reviewed-by: Daniel Vogelheim <vogelheim@chromium.org> Reviewed-by: Mason Freed <masonf@chromium.org> Commit-Queue: Michał Bentkowski <securitymb@google.com> Cr-Commit-Position: refs/heads/main@{#1498048} -- wpt-commits: 9c0aa5c663605b3ace87503917596acf132bca4f wpt-pr: 54184
29 lines
1.2 KiB
HTML
29 lines
1.2 KiB
HTML
<!DOCTYPE html>
|
|
<meta charset="utf-8">
|
|
<title>Spurious attributes in DOMParser</title>
|
|
<link rel="help" href="https://crbug.com/435995566">
|
|
<script src="/resources/testharness.js"></script>
|
|
<script src="/resources/testharnessreport.js"></script>
|
|
<body>
|
|
<script>
|
|
test(() => {
|
|
const html = `<div title="this-should-not-be-an-attribute=1>"hello"></div>`;
|
|
const doc = new DOMParser().parseFromString(html, "text/html");
|
|
const div = doc.querySelector("div");
|
|
|
|
assert_false(div.hasAttribute("this-should-not-be-an-attribute"));
|
|
assert_equals(div.getAttribute("title"), 'this-should-not-be-an-attribute=1>"hello');
|
|
}, 'Using ">" and HTML entities in an attribute creates no unexpected attributes.');
|
|
|
|
test(() => {
|
|
const html = `<div title="this-should-not-be-an-attribute=1>\rhello"></div>`;
|
|
const doc = new DOMParser().parseFromString(html, "text/html");
|
|
const div = doc.querySelector("div");
|
|
|
|
assert_false(div.hasAttribute("this-should-not-be-an-attribute"));
|
|
// Note: "\r" gets normalized to "\n" per https://infra.spec.whatwg.org/#normalize-newlines.
|
|
assert_equals(div.getAttribute("title"), 'this-should-not-be-an-attribute=1>\nhello');
|
|
}, 'Using ">" and "\\r" in an attribute creates no unexpected attributes.');
|
|
|
|
</script>
|