Skip to content

fix: harden escaping and devtools error responses - #10

Merged
phtn merged 1 commit into
mainfrom
fix/code-scanning-alerts
Oct 4, 2026
Merged

phtn merged 1 commit into
mainfrom
fix/code-scanning-alerts

Conversation

@phtn

@phtn phtn commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Escape all regex metacharacters in refactor identifier searches, preserve literal backslashes when encoding Tailwind arbitrary values, and strip SVG comments to a fixed point. Unexpected server exceptions now stay in the server console and produce a generic HTTP error instead of exposing internal details.

Addresses code-scanning alerts #1, #2, #3, #5, and #6.

Validation: bun run check passed, including typecheck, all 154 tests, and build. Added regression coverage for private exception details and literal backslashes in Tailwind values. git diff --check passed.

@phtn
phtn merged commit 12a41af into main Oct 4, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant