Files
sousa-gecko/testing/web-platform/tests/domparsing/domparser-spurious-attributes.html
T
Michał Bentkowski e446a4e66a Bug 1981658 [wpt PR 54184] - Fix ScanEscapedAttrValue, a=testonly
Automatic update from web-platform-tests
Fix ScanEscapedAttrValue

https://crrev.com/c/6491750 introduced a change, which deleted a crucial
line from ScanEscapedAttrValue(), which moved the `pos_` variable past
the quote character.

The effect of that is that the parser now treats the opening quote
character as the closing quote character and misparses the value of an
attribute, which can lead to spurious attributes.

See https://crbug.com/435995566 for details.

This CL adds this one line back and also adds a regression test to
ensure that this bug won't be re-introduced in the future.

Fixed: 435995566

Change-Id: I69d932d03f44652ccebb5362929bfe688340179e
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/6814951
Reviewed-by: Daniel Vogelheim <vogelheim@chromium.org>
Reviewed-by: Mason Freed <masonf@chromium.org>
Commit-Queue: Michał Bentkowski <securitymb@google.com>
Cr-Commit-Position: refs/heads/main@{#1498048}

--

wpt-commits: 9c0aa5c663605b3ace87503917596acf132bca4f
wpt-pr: 54184
2025-08-10 01:14:59 +00:00

29 lines
1.2 KiB
HTML

<!DOCTYPE html>
<meta charset="utf-8">
<title>Spurious attributes in DOMParser</title>
<link rel="help" href="https://crbug.com/435995566">
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<body>
<script>
test(() => {
const html = `<div title="this-should-not-be-an-attribute=1>&quot;hello"></div>`;
const doc = new DOMParser().parseFromString(html, "text/html");
const div = doc.querySelector("div");
assert_false(div.hasAttribute("this-should-not-be-an-attribute"));
assert_equals(div.getAttribute("title"), 'this-should-not-be-an-attribute=1>"hello');
}, 'Using ">" and HTML entities in an attribute creates no unexpected attributes.');
test(() => {
const html = `<div title="this-should-not-be-an-attribute=1>\rhello"></div>`;
const doc = new DOMParser().parseFromString(html, "text/html");
const div = doc.querySelector("div");
assert_false(div.hasAttribute("this-should-not-be-an-attribute"));
// Note: "\r" gets normalized to "\n" per https://infra.spec.whatwg.org/#normalize-newlines.
assert_equals(div.getAttribute("title"), 'this-should-not-be-an-attribute=1>\nhello');
}, 'Using ">" and "\\r" in an attribute creates no unexpected attributes.');
</script>