Skip to content

getTokenIndexes puts the section token into a regex unescaped #696

Description

@Jamie-BitFlight

What happens

src/readme-editor.ts, getTokenIndexes:

const startRegExp = new RegExp(startTokenFormat.replace('%s', token));
const stopRegExp = new RegExp(endTokenFormat.replace('%s', token));

The token is inserted raw. Any regex metacharacter in it changes the pattern.

Example in this repo

README.md and README.example.md carry <!-- start [.github/ghadocs/examples/] --> markers. In the pattern, [...] becomes a character class and . matches any character, so those markers can never match themselves.

Impact today

None reachable: every name in README_SECTIONS is plain letters. It becomes live the moment a section name carries ., [, ( or similar, and scripts/verify-readme-contract.mjs builds its patterns the same way.

Suggested direction

Escape the token before building the pattern, in the editor and in the verifier alike.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

releasedThis issue/pull request has been released.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions