fix: preserve caption transcripts containing delimiters and JavaScript escapes
Los mantenedores suelen responder en 1 día
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 66/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- javascript, typescript
- Área
- frontend
Línea de trabajo
Start in packages/studio/src/captions/parser.ts at extractTranscript and trace how the declaration is delimited, normalized, and parsed. Add regressions for delimiters inside strings, JavaScript hex escapes, escaped quotes, and malformed input; done means supported static literals preserve existing JSON, keys, commas, text, IDs, and timing behavior without evaluating executable expressions.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Caption transcript extraction silently returns an empty transcript for some valid JavaScript array literals.
For example, pass a composition containing this declaration to extractTranscript:
const TRANSCRIPT = [{ text: 'x ]; y', start: 0, end: 1 }];
Expected: one word with the literal text x ]; y. Actual: the extraction regex terminates at the delimiter inside the string, parsing fails, and the catch returns []. Independent review also reproduced failures for JavaScript hex escapes and certain escaped quotes in single-quoted words.
The implementation is in packages/studio/src/captions/parser.ts. Replace the delimiter/quote-normalization approach with a parser/tokenizer that accepts supported static array literals without evaluating code. Preserve existing JSON, single-quoted strings, unquoted keys, trailing commas, text, IDs and timing behavior; reject executable expressions. Add regressions for delimiters inside strings, escapes, and malformed input.
Found during the security cleanup and independently traced by miga-heygen. This is a correctness bug: parsed values reach JSON.parse/React text rendering, with no executable sink. Security alert #102 was individually classified as by design. The separate generated-script HTML boundary was fixed in #3847; that change does not fix this parser behavior.
- Lenguaje dominante
- TypeScript
- Estrellas
- 54.1k
- Forks
- 4.9k
- Merge medio
- 7 h 2 min
- PR fusionados (30 d)
- 782
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de heygen-com/hyperframes
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 84/100
heygen-com/hyperframes#5117 ·
Los mantenedores suelen responder en 1 día
-
Docs: clarify that "Enable auto-update" is only available in the Claude Code terminal (CLI) /plugin UIPosiblemente ocupada @rumi7911 la tomó hace 1 día. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
heygen-com/hyperframes#5027 ·
Los mantenedores suelen responder en 1 día
-
fix(producer): propagate useGpu to HDR layered streaming encoderPosiblemente ocupada @Monster-GM la tomó hace 3 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 87/100
heygen-com/hyperframes#5002 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
heygen-com/hyperframes#4702 · 1 comentario · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
Studio catalog prompt editor has no accessible namePosiblemente ocupada @lorenzozanee la tomó hace 13 días. Abiertobug difficulty/easy triage/ready
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
heygen-com/hyperframes#4384 ·
Los mantenedores suelen responder en 1 día
Todos los issues de heygen-com/hyperframes
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
rajbos/ai-engineering-fluency#2340 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
community documentation first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
Dificultad 1/5 Menos de una hora Aptitud para principiantes 70/100
lingdojo/kana-dojo#31864 · 1 comentario · 5 reacciones ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
zenstackhq/zenstack#2873 ·
Los mantenedores suelen responder en 1 día
-
CLI: TUI shows onboarding when the provider's API key is only in the environment (e.g. OPENROUTER_API_KEY)Posiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. AbiertoCLI
Dificultad 2/5 1-3 horas Aptitud para principiantes 67/100
cline/cline#14923 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
paperclipai/paperclip#15490 ·
Los mantenedores suelen responder en 1 día