fix(Typography): text is rendered as HTML tags when ellipsis is enabled#4117
Open
fix(Typography): text is rendered as HTML tags when ellipsis is enabled#4117
ellipsis is enabled#4117Conversation
Collaborator
TDesign Component Site Preview Open
|
commit: |
Contributor
There was a problem hiding this comment.
Pull request overview
This PR attempts to fix a security issue where HTML strings passed as children to Typography components with ellipsis enabled were being rendered as actual HTML elements instead of plain text. The fix adds an escapeHtml function that escapes HTML entities before processing the content for truncation.
Changes:
- Added
escapeHtmlmethod to sanitize HTML content before truncation processing - Modified
innerTextmethod to escape HTML fromnode.innerHTMLbefore further processing - Addresses XSS vulnerability where user-provided HTML strings could be executed
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
03cc928 to
b130d8d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

🤔 这个 PR 的性质是?
🔗 相关 Issue
💡 需求背景和解决方案
📝 更新日志
tdesign-react
ellipsis时,字符串被渲染为 HTML 标签的问题@tdesign-react/chat
☑️ 请求合并前的自查清单