Attribute selector with no valid attribute name throws a raw TypeError, or emits the text "undefined"
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 74/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Ít trao đổi
- Công nghệ
- javascript
- Lĩnh vực
- tooling
Hướng nghiên cứu
Start in src/parser.js at Parser#attribute and reproduce the listed selectors, including [ns|] and [ * ]. Compare the results with the existing [] parser error; done means invalid attribute selectors consistently produce the parser's own error, without a raw TypeError or literal "undefined" output.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Parser#attribute looks ahead to the next token without checking that one exists, and never verifies that an attribute name was actually captured. Two symptoms follow.
1. Raw TypeError when the last token before ] is *, $, ^, ~ or |
const parser = require("postcss-selector-parser");
parser().astSync("[ns|*]");
// TypeError: Cannot read properties of undefined (reading '0')
// at Parser.attribute (dist/parser.js:255:29)
Same crash for [a*], [a$], [a^], [a~], [a|], [|*], [*|*], [a|*], [ns|$], [ns|^].
These inputs are invalid CSS, so an error is correct, but it should be the parser's own error rather than a TypeError escaping from internals. This is the same class of defect as #329, at a different site: there the token stream ran out before a closing bracket, here it runs out before the lookahead in the token loop.
The four unguarded reads are in src/parser.js inside attribute():
case tokens.asterisk:
if (next[TOKEN.TYPE] === tokens.equals) { // next may be undefined
case tokens.caret: // reached by dollar via fall-through
if (next[TOKEN.TYPE] === tokens.equals) { // next may be undefined
case tokens.combinator:
if (content === "~" && next[TOKEN.TYPE] === tokens.equals) { // next may be undefined
...
if (next[TOKEN.TYPE] === tokens.equals) { // next may be undefined
Two other reads of next[TOKEN.TYPE] in the same file already guard with next &&, so the pattern is established. The else if immediately below the asterisk case also guards with && next, which suggests the possibility was known at the time.
2. The literal string undefined in the output when no attribute name is captured
parser().astSync("[ * ]").toString();
// "[ *|undefined]" <- an attribute name of "undefined", and a "|" that was never written
parser().astSync("[ * ]").toString();
// "[ *|undefined]"
attribute() ends with this.newNode(new Attribute(node)) with no check that node.attribute was ever set. When it was not, Attribute#toString interpolates the missing value, so a selector containing the text undefined is emitted. [*] on its own already throws Expected an attribute., so the two are inconsistent.
Guarding the four lookaheads alone converts most of the crashes in the first section into this second failure instead, so the two need addressing together.
Scale
Comparing 43,200 generated attribute selectors against 7.1.5:
- 341 produce a raw
TypeError - 596 produce output containing the literal text
undefined
Expected
An attribute selector with no valid attribute name should produce the parser's own error, consistent with [*], rather than a TypeError or a stringified undefined.
Version
Reproduced on 7.1.5 (current latest) and on main at e33e9bc.
- Ngôn ngữ chính
- JavaScript
- Star
- 215
- Fork
- 66
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của postcss/postcss-selector-parser
-
Using @csstools/css-tokenizerĐang mở
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
-
[tentative] Add support for `.foo-*` class prefix selectorsCó thể đã có người làm @MoOx đã nhận 53 ngày trước. Đang mở
postcss/postcss-selector-parser#332 · 1 reaction · 2 người được giao ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 45/100
postcss/postcss-selector-parser#309 · 1 bình luận ·
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100
postcss/postcss-selector-parser#306 · 2 bình luận ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 25/100
postcss/postcss-selector-parser#299 · 1 bình luận ·
Tất cả issue của postcss/postcss-selector-parser
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 90/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Design only Leadership Survey SLFS
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
bcgov/digital-journeys#2293 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
tursodatabase/turso#9405 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Toolkit
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
Maintainer thường phản hồi trong vòng 1 ngày
-
API Bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
ProjectSidewalk/SidewalkWebpage#5556 ·
Maintainer thường phản hồi trong vòng 1 ngày