Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

fix: preserve caption transcripts containing delimiters and JavaScript escapes

未关闭
#3,852 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

@AksharP5 已经在做这个了。

开始于 2026年9月12日。

  • #3896 来自 @AksharP5 —— 未关闭

评估

难度
4/5
预计耗时
3-5 天
新手友好度
66/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
活跃
领域
frontend

调研方向

Start in packages/studio/src/captions/parser.ts at extractTranscript and trace how the declaration is delimited, normalized, and parsed. Add regressions for delimiters inside strings, JavaScript hex escapes, escaped quotes, and malformed input; done means supported static literals preserve existing JSON, keys, commas, text, IDs, and timing behavior without evaluating executable expressions.

由索引模型根据 Issue 内容生成。

描述

triage/needs-triage

Caption transcript extraction silently returns an empty transcript for some valid JavaScript array literals.

For example, pass a composition containing this declaration to extractTranscript:

const TRANSCRIPT = [{ text: 'x ]; y', start: 0, end: 1 }];

Expected: one word with the literal text x ]; y. Actual: the extraction regex terminates at the delimiter inside the string, parsing fails, and the catch returns []. Independent review also reproduced failures for JavaScript hex escapes and certain escaped quotes in single-quoted words.

The implementation is in packages/studio/src/captions/parser.ts. Replace the delimiter/quote-normalization approach with a parser/tokenizer that accepts supported static array literals without evaluating code. Preserve existing JSON, single-quoted strings, unquoted keys, trailing commas, text, IDs and timing behavior; reject executable expressions. Add regressions for delimiters inside strings, escapes, and malformed input.

Found during the security cleanup and independently traced by miga-heygen. This is a correctness bug: parsed values reach JSON.parse/React text rendering, with no executable sink. Security alert #102 was individually classified as by design. The separate generated-script HTML boundary was fixed in #3847; that change does not fix this parser behavior.

主要语言
TypeScript
星标
54.1k
派生
4.9k
平均合并
7 小时 29 分钟
30 天内合并 PR
778

环境准备

这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

heygen-com/hyperframes 的其他 Issue

查看 heygen-com/hyperframes 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。