Conversation
|
@nrps9909 is attempting to deploy a commit to the afc163's projects Team on Vercel. A member of the Team first needs to authorize it. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review. Walkthrough动态 CSS 注入和更新改用 Changes动态 CSS 兼容性
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix · Severity of issue fixed: Medium Merge Risk: ⚪ Minimal · up to The change avoids TrustedHTML restrictions during stylesheet injection while preserving CSS text and existing update behavior. No actionable merge-blocking risk remains in the supplied evidence. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change treats stylesheet content as text while preserving existing style ownership, insertion order, and CSP nonce handling. No introduced security defect is established. Downstream CSS trust policies and behavior under actual browser policy enforcement remain unverified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. 小兔写入 textContent, Comment |
5c6618f to
fd34914
Compare
|
Resolved the conflict against current master Rechecked base/head: the TrustedHTML regression fails on base (209 other tests pass), while the fix passes all 31 suites / 210 tests with one existing skip. TypeScript, ESM/CJS/declaration builds, focused lint (0 errors, 1 existing warning), formatting and diff checks pass. An independent Chromium 151.0.7922.34 probe with an actual |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #809 +/- ##
=======================================
Coverage 86.94% 86.94%
=======================================
Files 41 41
Lines 1111 1111
Branches 404 396 -8
=======================================
Hits 966 966
Misses 143 143
Partials 2 2 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Fixes #555.
injectCSSand the existing-node path inupdateCSSuseHTMLStyleElement.innerHTML, which throws when the host document enforces Trusted Types. Writing and comparing CSS throughtextContentallows stylesheet injection and updates under that policy without a TrustedHTML policy.The regression blocks the style
innerHTMLsetter and covers initial injection and updates to an existing managed style. The patch is based on current master993255ed15595875a7004033c3e8f7b892586dea; the recently merged missing-container guards and their tests are retained. Only the original two files change (38 insertions, 3 deletions).Validation on Node 26.10.0, pnpm 11.21.0, TypeScript 6.0.3:
require-trusted-types-for 'script'; trusted-types 'none'. Both initial injection and preexisting-node updates throw on base and pass after the fix. The unsafe-setter control stays blocked in both versions. CSS text/computed color, nonce, node identity and no duplicate managed styles are verified.These are local results; upstream CI and maintainer review remain separate, and this PR is still open.
AI assistance disclosure: Codex helped trace the sink, resolve the upstream test conflict, run base/head validation and the independent Chromium probe, and prepare this description. The final diff and results were checked against the recorded commits.
Summary by CodeRabbit
Bug Fixes
Tests