Skip to content

Commit 7d0001a

Browse files
committed
test(viewer): read the rendered handler tag from the regex capture group
CodeQL flags the `replace('<', '')` as incomplete sanitization. The match always starts with a single '<', but using the existing capture group is both clearer and avoids the false positive. Assisted-by: ClaudeCode:claude-opus-4-8 Signed-off-by: skjnldsv <skjnldsv@protonmail.com>
1 parent 4e34264 commit 7d0001a

1 file changed

Lines changed: 1 addition & 2 deletions

File tree

‎apps/viewer/test/component/mountViewer.ts‎

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -128,8 +128,7 @@ export function mountViewer(handlers: IHandler[] = []): MountViewerResult {
128128

129129
const renderedTags = () => {
130130
const html = wrapper.html()
131-
const matches = html.match(/<(oca-viewer-[a-z0-9-]+)/g) ?? []
132-
return matches.map((m) => m.replace('<', ''))
131+
return [...html.matchAll(/<(oca-viewer-[a-z0-9-]+)/g)].map(([, tag]) => tag)
133132
}
134133

135134
return {

0 commit comments

Comments
 (0)