Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

profiler-ui.js and profiler-compare.js accept a file by MIME type but dispatch on filename extension only, silently misparsing it

Chiusa Adatta ai principianti
#700 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
75/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
javascript
Ambito
frontend, tooling

Direzione di ricerca

Il problema si trova in assets/profiler-ui.js e assets/profiler-compare.js. Osservate le funzioni readFile e runText. La soluzione consiste nell'allineare la logica di dispatch del parsing con i controlli di accettazione dei file, utilizzando sia file.name che file.type. Iniziate leggendo il codice esistente di accept-gate, quindi aggiornate i rami che analizzano JSON e XLSX. Testate caricando file con tipi MIME corretti ma estensioni non corrispondenti e verificate che vengano analizzati correttamente o che generino un errore in modo pulito.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

bug

Where: assets/profiler-ui.js's readFile()/runText() and assets/profiler-compare.js's readFile().

The gap: In both files, the accept-gate is:

var okExt = /\.(csv|tsv|json|xlsx)$/i.test(file.name);
var okType = file.type === 'text/csv' || file.type === 'text/tab-separated-values' ||
  file.type === 'application/json' ||
  file.type === 'application/vnd.openxmlformats-officedocument.spreadsheetml.sheet';
if (!okExt && !okType) { ... reject ... }

So a file is accepted if its MIME type alone matches, even with no matching extension (e.g. an extensionless download, or a file whose name lost its extension but whose OS-reported type didn't). But once accepted, both files decide how to parse purely by extension:

  • profiler-ui.js's readFile() routes to parseXLSX only if /\.xlsx$/i.test(file.name), otherwise reads as text and calls runText(), which does if (/\.json$/i.test(name)) parseJSON(text); else parseCSV(text); - file.type is never consulted here, even though it was just used to accept the file two functions up.
  • profiler-compare.js's readFile() has the same /\.xlsx$/i.test(file.name) branch for the ArrayBuffer/XLSX path, ignoring file.type there too (its JSON branch does correctly check both name and type - only the xlsx path has this gap).

Neither misrouting throws a clean error - both silently return a garbage table.

Repro:

$ node -e "
require('./assets/profiler-engine.js');
var text = JSON.stringify([{sex:'M',race:'White',age:25},{sex:'F',race:'Black',age:30}]);
var t = global.FairCodeProfiler.parseCSV(text);
console.log(JSON.stringify(t));
"
{"columns":["[{\"sex\":\"M\"","race:\"White\"","age:25}","{\"sex\":\"F\"","race:\"Black\"","age:30}]"],"rows":[]}

No exception - a JSON file accepted via file.type === 'application/json' but lacking a .json name gets silently parsed into a 0-row table of garbled column names instead of erroring. Same result for xlsx bytes read as text - 207 bogus rows from binary xlsx content, again with no error raised. For a fairness-auditing tool, a silent nonsense profile is worse than a clean rejection.

Fix direction: Make the dispatch condition in runText() (profiler-ui.js) and the xlsx branch in both readFile()s check file.type the same way the accept-gate and the already-correct call sites do (profiler-ui.js's own reference-baseline loader, and profiler-compare.js's JSON branch): /\.json$/i.test(name) || file.type === 'application/json', and analogously for xlsx.

Lingua principale
HTML
Stelle
47
Fork
45
Merge medio
1h 56m
PR unite (30g)
97

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di yakew7/Fair-Code

Tutte le issue di yakew7/Fair-Code

Issue simili

Altre issue su Web Dev

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.