Commit 05f7dc1
fix: decode ES2015+ \u{...} extended unicode escapes in jsDecode (#1657)
* fix: decode ES2015+ \u{...} extended unicode escapes in jsDecode
doJsDecode only recognized \uHHHH (exactly 4 hex digits). The \u{H...H}
extended code point escape (1-6 hex digits in braces), supported by
every modern JS engine since ES2015, fell through to the generic
escape branch: the backslash was dropped and the literal "u" kept,
leaving the rest ("{H...H}") uncorrected in the output -- so a keyword
spelled with \u{...} escapes (e.g. \u{61}\u{6c}\u{65}\u{72}\u{74} for
"alert") never got decoded at all.
See #1653
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* fix: fold full-width ASCII in \u{...} regardless of leading zeros
The full-width-ASCII fold only applied when the escape had exactly 4
hex digits, so a leading-zero encoding of the same value -- \u{0ff01}
or \u{00ff01}, both numerically U+FF01 -- skipped the fold entirely
and decoded to the raw low byte instead of '!'. Trivially defeats the
fold's purpose (normalizing fullwidth-character evasion).
Now computes the fully resolved code point (same approach as
cssDecode's fix in #1658) and checks the fold range against that
value directly, independent of digit count or leading zeros.
Found by CodeRabbit review on this PR.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>1 parent 8639d3e commit 05f7dc1
2 files changed
Lines changed: 133 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
33 | 33 | | |
34 | 34 | | |
35 | 35 | | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
36 | 43 | | |
37 | 44 | | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
38 | 71 | | |
39 | 72 | | |
40 | 73 | | |
| |||
131 | 164 | | |
132 | 165 | | |
133 | 166 | | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
29 | 113 | | |
30 | 114 | | |
31 | 115 | | |
| |||
50 | 134 | | |
51 | 135 | | |
52 | 136 | | |
| 137 | + | |
53 | 138 | | |
54 | 139 | | |
55 | 140 | | |
| |||
0 commit comments