Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

fix: preserve caption transcripts containing delimiters and JavaScript escapes

Aperta
#3,852 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

@AksharP5 ci sta già lavorando.

Dal 12/9/2026.

  • #3896 di @AksharP5 — aperta

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
66/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
javascript, typescript
Ambito
frontend

Direzione di ricerca

Start in packages/studio/src/captions/parser.ts at extractTranscript and trace how the declaration is delimited, normalized, and parsed. Add regressions for delimiters inside strings, JavaScript hex escapes, escaped quotes, and malformed input; done means supported static literals preserve existing JSON, keys, commas, text, IDs, and timing behavior without evaluating executable expressions.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

triage/needs-triage

Caption transcript extraction silently returns an empty transcript for some valid JavaScript array literals.

For example, pass a composition containing this declaration to extractTranscript:

const TRANSCRIPT = [{ text: 'x ]; y', start: 0, end: 1 }];

Expected: one word with the literal text x ]; y. Actual: the extraction regex terminates at the delimiter inside the string, parsing fails, and the catch returns []. Independent review also reproduced failures for JavaScript hex escapes and certain escaped quotes in single-quoted words.

The implementation is in packages/studio/src/captions/parser.ts. Replace the delimiter/quote-normalization approach with a parser/tokenizer that accepts supported static array literals without evaluating code. Preserve existing JSON, single-quoted strings, unquoted keys, trailing commas, text, IDs and timing behavior; reject executable expressions. Add regressions for delimiters inside strings, escapes, and malformed input.

Found during the security cleanup and independently traced by miga-heygen. This is a correctness bug: parsed values reach JSON.parse/React text rendering, with no executable sink. Security alert #102 was individually classified as by design. The separate generated-script HTML boundary was fixed in #3847; that change does not fix this parser behavior.

Lingua principale
TypeScript
Stelle
54.1k
Fork
4.9k
Merge medio
7h 29m
PR unite (30g)
778

Preparare l'ambiente

Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di heygen-com/hyperframes

Tutte le issue di heygen-com/hyperframes

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.