Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

fix: preserve caption transcripts containing delimiters and JavaScript escapes

Abierto
#3,852 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

@AksharP5 ya está trabajando en esto.

Desde el 12/9/2026.

  • #3896 de @AksharP5 — abierto

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
66/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
javascript, typescript
Área
frontend

Línea de trabajo

Start in packages/studio/src/captions/parser.ts at extractTranscript and trace how the declaration is delimited, normalized, and parsed. Add regressions for delimiters inside strings, JavaScript hex escapes, escaped quotes, and malformed input; done means supported static literals preserve existing JSON, keys, commas, text, IDs, and timing behavior without evaluating executable expressions.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

triage/needs-triage

Caption transcript extraction silently returns an empty transcript for some valid JavaScript array literals.

For example, pass a composition containing this declaration to extractTranscript:

const TRANSCRIPT = [{ text: 'x ]; y', start: 0, end: 1 }];

Expected: one word with the literal text x ]; y. Actual: the extraction regex terminates at the delimiter inside the string, parsing fails, and the catch returns []. Independent review also reproduced failures for JavaScript hex escapes and certain escaped quotes in single-quoted words.

The implementation is in packages/studio/src/captions/parser.ts. Replace the delimiter/quote-normalization approach with a parser/tokenizer that accepts supported static array literals without evaluating code. Preserve existing JSON, single-quoted strings, unquoted keys, trailing commas, text, IDs and timing behavior; reject executable expressions. Add regressions for delimiters inside strings, escapes, and malformed input.

Found during the security cleanup and independently traced by miga-heygen. This is a correctness bug: parsed values reach JSON.parse/React text rendering, with no executable sink. Security alert #102 was individually classified as by design. The separate generated-script HTML boundary was fixed in #3847; that change does not fix this parser behavior.

Lenguaje dominante
TypeScript
Estrellas
54.1k
Forks
4.9k
Merge medio
7 h 2 min
PR fusionados (30 d)
782

Preparar el entorno

Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de heygen-com/hyperframes

Todos los issues de heygen-com/hyperframes

Issues similares

Más issues de TypeScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.