Bug: HTML entity replacements missing semicolons (</>) — sliced entities render as garbage text in typed-word overlay
Maintainers usually reply within 1 day
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 84/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- typescript
- Domain
- frontend
Research direction
Start by reading the two call sites in frontend/src/ts/test/result-word-highlight.ts and frontend/src/ts/test/test-ui.ts, then inspect Misc.escapeHTML in utils/misc.ts:137-145. Ensure both overlay paths escape the angle brackets before slicing without producing truncated entity text, and verify the reproduction no longer renders raw fragments such as &l.
Written by the indexing model from the issue text.
Description
Did you clear cache before opening an issue?
- I have cleared my cache
Is there an existing issue for this?
- I have searched the existing open and closed issues
Does the issue happen when logged in?
Yes
Does the issue happen when logged out?
Yes
Does the issue happen in incognito mode when logged in?
Yes
Does the issue happen in incognito mode when logged out?
Yes
Issue details
Current Behavior
Two spots replace < / > with HTML entities but omit the trailing semicolon, producing non-standard references that interact badly with .slice():
// frontend/src/ts/test/result-word-highlight.ts:314-319
inputWordEl.innerHTML = userInputString
.replace(/\t/g, "_")
.replace(/</g, "<") // no semicolon
.replace(/>/g, ">") // no semicolon
.slice(0, wordEl.childElementCount);
// frontend/src/ts/test/test-ui.ts:1405-1409 — same pattern
Because the slice happens after replacement, input ending in < gets truncated mid-entity (e.g. &l), which then renders as literal garbage text instead of <. Legacy-style semicolon-less entities also double-decode oddly when adjacent entity-like text exists in the typed string.
Expected Behavior
Replace before slicing with proper entities (or escape after slicing):
.replace(/</g, "<")
.replace(/>/g, ">")
Ideally both call sites would share one escaping helper (e.g. reuse Misc.escapeHTML from utils/misc.ts:137-145, which already escapes correctly).
Steps To Reproduce
- Type a word containing
<such that the input length exceeds the word length so.slice()cuts inside the appended entity (e.g. typeabc<against wordxyz). - Observe raw
&lfragments rendered in the input overlay instead of the<character.
Environment
- OS: Any
- Browser: Any
- Found via source review of
master@ 91bd24bb8
- Dominant language
- TypeScript
- Stars
- 20.8k
- Forks
- 3.4k
- Avg merge
- 1d 52m
- Merged PRs (30d)
- 2
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from monkeytypegame/monkeytype
-
bug
Difficulty 1/5 Under an hour Newbie friendliness 85/100
monkeytypegame/monkeytype#8446 · 1 comment ·
Maintainers usually reply within 1 day
-
[Low Priority] Word Filter silently fails when an invalid regex is enteredPossibly taken @MFA-G claimed this 13 days ago. Openbug
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
monkeytypegame/monkeytype#8422 ·
Maintainers usually reply within 1 day
-
Bug: outOfFocusTimeouts array grows unboundedly — cleared timeout ids never removed from arrayPossibly taken @priyanshu1976 claimed this 38 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
monkeytypegame/monkeytype#8366 ·
Maintainers usually reply within 1 day
-
Bug (backend): dead null check in newQuotes.approve() — git === null never true, git init failure crashes with raw TypeErrorPossibly taken @boergeson claimed this 38 days ago. Open
Difficulty 1/5 Under an hour Newbie friendliness 88/100
monkeytypegame/monkeytype#8364 · 1 comment ·
Maintainers usually reply within 1 day
-
Bug (backend): cacheWithTTL marks cache fresh before fetch resolves — failed fetch serves stale data for full TTL, no in-flight dedupPossibly taken @boergeson claimed this 39 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
monkeytypegame/monkeytype#8363 ·
Maintainers usually reply within 1 day
All issues in monkeytypegame/monkeytype
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
wardian-app/Wardian#1603 ·
Maintainers usually reply within 1 day
-
Sign the pledgeOpen
Difficulty 1/5 Under an hour Newbie friendliness 85/100
input-output-hk/devx-updates#168 ·
Maintainers usually reply within 1 day
-
triage
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
github/docs#46222 · 1 comment ·
Maintainers usually reply within 1 day
-
agent-ready area: config area: skills type: chore upstream: brain-kit
Difficulty 1/5 Under an hour Newbie friendliness 95/100
-
dev experience frontend good first issue
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
cuttle-cards/cuttle#1403 ·
Maintainers usually reply within 1 day