fix(editor): avoid unsafe clipboard parsing pattern (#3474)

This commit is contained in:
Amruth Pillai
2026-09-05 20:06:23 -07:00
committed by GitHub
parent 2a4a1583be
commit 97f34b7ccd
3 changed files with 3 additions and 4 deletions
@@ -53,8 +53,7 @@ const isPreservableTextBlock = (node: ProseMirrorNode) =>
// Mark real text blocks before ProseMirror collapses their whitespace. Containers
// that its parser turns into paragraphs need the same explicit block boundary.
const markPastedHtml = (html: string) => {
const root = document.createElement("div");
root.innerHTML = html;
const root = new DOMParser().parseFromString(html, "text/html").body;
const blockTags = /^(P|H[1-6]|DIV|BLOCKQUOTE|UL|OL|LI|PRE|HR|TABLE)$/;
const normalize = (container: HTMLElement) => {
let paragraph: HTMLParagraphElement | undefined;
@@ -28,7 +28,7 @@ describe("normalizeRichTextHtml", () => {
it("does not reinterpret marked RTL line breaks as pseudo-bullet lists", () => {
const html = '<p data-resume-whitespace="preserve"> - First<br> - Second</p>';
expect(normalizeRichTextHtml(html, { direction: "rtl" })).toBe(
'<p data-resume-whitespace="preserve">‏ - First<br> - Second</p>',
'<p data-resume-whitespace="preserve">\u200f - First<br> - Second</p>',
);
});
@@ -148,7 +148,7 @@ const isInlineNode = (node: Node): boolean => {
};
// Allow optional leading whitespace + LRM/RLM marks before the bullet character.
const PSEUDO_BULLET_LEAD = /^[\s‎‏]*[-•*]\s+/;
const PSEUDO_BULLET_LEAD = /^[\s\u200e\u200f]*[-•*]\s+/;
const stripEmptyInlineWrappers = (html: string): string =>
html.replace(/<(strong|b|em|i|u|span)\b[^>]*>\s*<\/\1>/gi, "");