From acdb9d88d3ebb939c163d0bca169bf71d59a1c37 Mon Sep 17 00:00:00 2001 From: Amruth Pillai Date: Tue, 29 Sep 2026 22:06:30 +0200 Subject: [PATCH] fix(import): escape plain-text fields from json resume Summaries, highlights, courses, and award, publication and reference texts went into the HTML as written, so text such as "C" was lost. They now go through the same escapeHtml helper as the LinkedIn and plain-text importers. --- packages/import/src/html.test.ts | 9 ++++----- packages/import/src/html.ts | 10 +++++----- packages/import/src/json-resume.test.ts | 16 ++++++++++++++++ packages/import/src/json-resume.tsx | 8 ++++---- 4 files changed, 29 insertions(+), 14 deletions(-) diff --git a/packages/import/src/html.test.ts b/packages/import/src/html.test.ts index 8d61a181d..0b2625d2e 100644 --- a/packages/import/src/html.test.ts +++ b/packages/import/src/html.test.ts @@ -31,9 +31,8 @@ describe("toHtmlDescription", () => { expect(toHtmlDescription("", ["a"])).toBe(""); }); - it("does not escape HTML in inputs (caller's responsibility)", () => { - // Document existing behavior: caller must sanitize before passing - expect(toHtmlDescription("