Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

profiler-ui.js and profiler-compare.js accept a file by MIME type but dispatch on filename extension only, silently misparsing it

Closed Beginner friendly
#700 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
75/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
javascript
Domain
frontend, tooling

Research direction

The issue is in assets/profiler-ui.js and assets/profiler-compare.js. Look at the readFile and runText functions. The fix is to align the parsing dispatch logic with the file acceptance checks, using both file.name and file.type. Start by reading the existing accept-gate code, then update the branches that parse JSON and XLSX. Test by uploading files with correct MIME types but mismatched extensions and verifying they parse correctly or error cleanly.

Written by the indexing model from the issue text.

Description

bug

Where: assets/profiler-ui.js's readFile()/runText() and assets/profiler-compare.js's readFile().

The gap: In both files, the accept-gate is:

var okExt = /\.(csv|tsv|json|xlsx)$/i.test(file.name);
var okType = file.type === 'text/csv' || file.type === 'text/tab-separated-values' ||
  file.type === 'application/json' ||
  file.type === 'application/vnd.openxmlformats-officedocument.spreadsheetml.sheet';
if (!okExt && !okType) { ... reject ... }

So a file is accepted if its MIME type alone matches, even with no matching extension (e.g. an extensionless download, or a file whose name lost its extension but whose OS-reported type didn't). But once accepted, both files decide how to parse purely by extension:

  • profiler-ui.js's readFile() routes to parseXLSX only if /\.xlsx$/i.test(file.name), otherwise reads as text and calls runText(), which does if (/\.json$/i.test(name)) parseJSON(text); else parseCSV(text); - file.type is never consulted here, even though it was just used to accept the file two functions up.
  • profiler-compare.js's readFile() has the same /\.xlsx$/i.test(file.name) branch for the ArrayBuffer/XLSX path, ignoring file.type there too (its JSON branch does correctly check both name and type - only the xlsx path has this gap).

Neither misrouting throws a clean error - both silently return a garbage table.

Repro:

$ node -e "
require('./assets/profiler-engine.js');
var text = JSON.stringify([{sex:'M',race:'White',age:25},{sex:'F',race:'Black',age:30}]);
var t = global.FairCodeProfiler.parseCSV(text);
console.log(JSON.stringify(t));
"
{"columns":["[{\"sex\":\"M\"","race:\"White\"","age:25}","{\"sex\":\"F\"","race:\"Black\"","age:30}]"],"rows":[]}

No exception - a JSON file accepted via file.type === 'application/json' but lacking a .json name gets silently parsed into a 0-row table of garbled column names instead of erroring. Same result for xlsx bytes read as text - 207 bogus rows from binary xlsx content, again with no error raised. For a fairness-auditing tool, a silent nonsense profile is worse than a clean rejection.

Fix direction: Make the dispatch condition in runText() (profiler-ui.js) and the xlsx branch in both readFile()s check file.type the same way the accept-gate and the already-correct call sites do (profiler-ui.js's own reference-baseline loader, and profiler-compare.js's JSON branch): /\.json$/i.test(name) || file.type === 'application/json', and analogously for xlsx.

Dominant language
HTML
Stars
47
Forks
45
Avg merge
1h 53m
Merged PRs (30d)
97

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from yakew7/Fair-Code

All issues in yakew7/Fair-Code

Similar issues

More Web Dev issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.