Conversation
…loud chapter-list failures, direct cover URLs
|
| const unquoted = val.replace(/^['"]|['"]$/g, ''); | ||
| return /^\s*javascript:/i.test(unquoted) ? '' : _m; |
There was a problem hiding this comment.
Encoded script links survive If chapter HTML contains a link such as
<a href="javascript:alert(1)">, this check leaves it intact because it tests the encoded text. The reader renders the returned HTML directly, so clicking the link can execute script. How this was verified: The URL check preserves the encoded attribute, and the reader inserts the returned chapter HTML with dangerouslySetInnerHTML.
| const root = safeJson(jsonText); | ||
| const items: ChapterInfo[] = []; | ||
| let lastPage = 1; | ||
| if (isRecord(root)) { |
There was a problem hiding this comment.
Malformed pages truncate chapters If a later free-chapter request returns a nonblank error page or malformed JSON, it passes the blank-response check. This parser then returns no chapters and defaults
lastPage to 1, so parseNovel stops fetching pages and presents an incomplete chapter list as though it were complete.
| const blocks = body.match( | ||
| /<p[\s\S]*?<\/p>|<h[1-6][\s\S]*?<\/h[1-6]>|<figure[\s\S]*?<\/figure>|<img[^>]*>/gi, | ||
| ) || [body]; |
There was a problem hiding this comment.
Unmatched chapter content disappears If a chapter mixes paragraphs with a list, table, or text in another unsupported container,
body.match() keeps only the recognized blocks. For example, <p>Introduction</p><ul><li>Important note</li></ul> loses the note, so the reader displays an incomplete chapter.
| .replace(/^<p[^>]*>/i, '') | ||
| .replace(/<\/p>$/i, '') | ||
| .trim(); | ||
| return /^<strong>[\s\S]*<\/strong>$/.test(inner); |
There was a problem hiding this comment.
|
Addressed the new review findings:
|
Follow-up to #2588 (merged with the pre-fix version). Addresses the review-bot findings on plugins/english/wetriedtls.ts:
No test files added, per your note on #2575.