Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Decide: restore html-comment-strip broad sweep with framework-marker allowlist

オープン
#178 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 3 日以内に返信

まだ誰も着手していません。

評価

難易度
5/5
見積もり時間
1週間以上
初心者へのやさしさ
30/100
issue の種類
機能追加
明瞭さ
説明が足りない
活発さ
静か
技術スタック
typescript
領域
security

調査の方向性

Start by reading issue #176 and the current html-comment-strip behavior, including the INJECTION_PATTERNS set and its blanking semantics. Catalog the framework marker shapes and SSR or license comments named in this issue, then document whether a stable allowlist supports restoring the broad sweep. Done means a clear decision about the behavior and the risks of keeping the allowlist synchronized.

索引モデルが issue の本文から書いたものです。

説明

enhancement question

Follow-up to #176.

Before #176, html-comment-strip removed every comment outside <script> / <style> / <noscript>. After #176, it scrubs only comments whose data matches the INJECTION_PATTERNS set (currently 11 patterns) — and blanks them in place rather than detaching. The narrowing is what makes React Suspense markers ($, /$, $?, $!, [, ], …) safe automatically: they don't match any pattern, so they're left alone, and the framework's unmount walk doesn't trip on a missing node.

Tradeoff

Narrowing to pattern matches caps coverage at the recognized shapes. Novel injection phrasings, off-pattern prose, and benign-looking comments carrying instruction-shaped text — all of which used to be removed — now stay visible.

Decision needed

Should we restore broad-sweep behavior with a framework-marker allowlist (skip $ / /$ / [ / ]-prefixed data, plus any other markers we identify), and continue blanking via comment.data = \"\" rather than detaching?

Tradeoffs to weigh:

  • For: restores pre-#176 coverage for off-pattern injection prose; reduces dependence on INJECTION_PATTERNS keeping pace with attacker phrasing.
  • Against: allowlist enumeration becomes load-bearing — a missed framework marker re-introduces the navigation crash class through a different path. Frameworks evolve their hydration marker syntax over time (React 18 → 19 changed marker shapes); we'd need a story for keeping the allowlist in sync.

Either way, no detach — the carrier stays attached.

Suggested next step

Catalog the marker shapes currently in the wild (React 18/19, Vue 3, Svelte 4/5, Astro islands, htmx, Lit hydration) and a few SSR build stamps / license headers we don't want to touch, then re-evaluate whether the allowlist is small/stable enough to be worth the broad sweep.

主要言語
TypeScript
スター
34
フォーク
3
平均マージ
3日 3時間
マージ済み PR(30日)
35

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

pixiebrix/agent-browser-shield のほかの issue

pixiebrix/agent-browser-shield の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。