Skip to content

fix(lint): do not treat text inside quoted attributes as boolean attribute names (#4381) - #4878

Closed
Adarsh-mk7 wants to merge 1 commit into
heygen-com:mainfrom
Adarsh-mk7:fix/lint-quoted-boolean-attributes
Closed

Adarsh-mk7 wants to merge 1 commit into
heygen-com:mainfrom
Adarsh-mk7:fix/lint-quoted-boolean-attributes

Conversation

@Adarsh-mk7

Copy link
Copy Markdown

What

Make hasAttrName in @hyperframes/lint quote-aware by parsing HTML attributes via htmlparser2 instead of regex matching raw attribute text.

Problem and user impact

When an element contains text inside single- or double-quoted attributes (such as title="an unmuted muted clip" or aria-label="muted"), the linter misinterprets the text inside quotes as a muted attribute.

This causes:

  1. False negatives (suppression of real errors): An unmuted video element with text containing the word "muted" in a title or tooltip wrongly passes lint, suppressing both video_missing_muted and video_audio_double_source diagnostics. In production, unmuted videos that lack audio synchronization or cause audio echo pass lint undetected.
  2. False positives: Tooltips or descriptions containing words like crossorigin falsely trigger media_crossorigin_breaks_preview and fail validation.

Root cause

hasAttrName(tagSource, attr) in packages/lint/src/rules/media.ts stripped the leading tag name and ran new RegExp((?:^|\s)${escaped}(?:\s*=|\s|/?>), "i") directly over the raw attribute string. Because it did not parse attributes or track quote boundaries, any occurrence of an attribute name within quoted attribute values matched.

Solution

Replaced the unquoted regex scan in hasAttrName with htmlparser2's Parser. This:

  • Ensures attribute values enclosed in quotes cannot impersonate attribute names.
  • Preserves standard HTML boolean attribute semantics (bare attributes <video muted>, empty-string attributes <video muted="">, and valued boolean attributes like <video muted="false">).
  • Retains case-insensitive matching for HTML attribute names.

Related work

Fixes #4381

Test plan

  • Unit tests added/updated
    • Added test case verifying text inside quoted attributes does not satisfy muted check, properly reporting video_missing_muted and video_audio_double_source.
    • Added test case verifying bare, valued, and case-insensitive muted attributes are recognized.
    • Added test case verifying crossorigin inside a quoted attribute value does not trigger media_crossorigin_breaks_preview.
  • Manual testing performed

@miguel-heygen

Copy link
Copy Markdown
Collaborator

Thanks for the fix. #4396 addresses the same issue (#4381) and reuses the existing attribute parser, so we're consolidating there and closing this one as a duplicate.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

lint: text inside quoted attributes can suppress real muted diagnostics

2 participants