fix: preserve caption transcripts containing delimiters and JavaScript escapes
维护者通常 1 天内回复
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 66/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 活跃
- 技术栈
- javascript, typescript
- 领域
- frontend
调研方向
Start in packages/studio/src/captions/parser.ts at extractTranscript and trace how the declaration is delimited, normalized, and parsed. Add regressions for delimiters inside strings, JavaScript hex escapes, escaped quotes, and malformed input; done means supported static literals preserve existing JSON, keys, commas, text, IDs, and timing behavior without evaluating executable expressions.
由索引模型根据 Issue 内容生成。
描述
Caption transcript extraction silently returns an empty transcript for some valid JavaScript array literals.
For example, pass a composition containing this declaration to extractTranscript:
const TRANSCRIPT = [{ text: 'x ]; y', start: 0, end: 1 }];
Expected: one word with the literal text x ]; y. Actual: the extraction regex terminates at the delimiter inside the string, parsing fails, and the catch returns []. Independent review also reproduced failures for JavaScript hex escapes and certain escaped quotes in single-quoted words.
The implementation is in packages/studio/src/captions/parser.ts. Replace the delimiter/quote-normalization approach with a parser/tokenizer that accepts supported static array literals without evaluating code. Preserve existing JSON, single-quoted strings, unquoted keys, trailing commas, text, IDs and timing behavior; reject executable expressions. Add regressions for delimiters inside strings, escapes, and malformed input.
Found during the security cleanup and independently traced by miga-heygen. This is a correctness bug: parsed values reach JSON.parse/React text rendering, with no executable sink. Security alert #102 was individually classified as by design. The separate generated-script HTML boundary was fixed in #3847; that change does not fix this parser behavior.
- 主要语言
- TypeScript
- 星标
- 54.1k
- 派生
- 4.9k
- 平均合并
- 7 小时 29 分钟
- 30 天内合并 PR
- 778
环境准备
这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
heygen-com/hyperframes 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 85/100
heygen-com/hyperframes#5027 ·
维护者通常 1 天内回复
-
fix(producer): propagate useGpu to HDR layered streaming encoder可能已有人在做 @Monster-GM 于 1 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 87/100
heygen-com/hyperframes#5002 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 78/100
heygen-com/hyperframes#4702 · 1 条评论 · 1 个 reaction ·
维护者通常 1 天内回复
-
Studio catalog prompt editor has no accessible name可能已有人在做 @lorenzozanee 于 12 天前认领。 未关闭bug difficulty/easy triage/ready
难度 2/5 1-3 小时 新手友好度 78/100
heygen-com/hyperframes#4384 ·
维护者通常 1 天内回复
-
lint: validate composition variables declared on supported root elements可能重新可做 关联的 PR 已关闭且未合并。 未关闭bug difficulty/easy triage/ready
难度 2/5 1-3 小时 新手友好度 88/100
heygen-com/hyperframes#4383 ·
维护者通常 1 天内回复
查看 heygen-com/hyperframes 的全部 Issue
相似的 Issue
-
enhancement good first issue priority: low size: XS
难度 2/5 1-3 小时 新手友好度 82/100
维护者通常 1 天内回复
-
难度 1/5 1-3 小时 新手友好度 88/100
-
难度 1/5 1 小时以内 新手友好度 90/100
streamplace/streamplace#1351 ·
维护者通常 2 天内回复
-
automated issue report
难度 2/5 1-3 小时 新手友好度 66/100
databendlabs/databend-docs#3511 ·
-
automated issue report
难度 2/5 1-3 小时 新手友好度 65/100