fix(forms): sanitize multiple and IDN email values

This commit is contained in:
ldm0
2026-09-27 07:48:58 +08:00
parent 6048b0e1cd
commit 4840ded1f6
6 changed files with 24 additions and 22 deletions
@@ -3085,8 +3085,6 @@ html/semantics/forms/form-submission-target/rel-form-target.html
html/semantics/forms/form-submission-target/rel-input-target.html
html/semantics/forms/textfieldselection/selection.html
html/semantics/forms/the-button-element/button-click-submits-with-commandfor.html
html/semantics/forms/the-input-element/email-value-idn.html
html/semantics/forms/the-input-element/email.html
html/semantics/forms/the-input-element/input-type-button.html
html/semantics/forms/the-input-element/range-2.html
html/semantics/forms/the-input-element/range.html
@@ -6359,6 +6359,8 @@ html/semantics/forms/the-input-element/datetime-local-valueasdate.html
html/semantics/forms/the-input-element/datetime-local.html
html/semantics/forms/the-input-element/datetime-weekmonth.html
html/semantics/forms/the-input-element/datetime.html
html/semantics/forms/the-input-element/email-value-idn.html
html/semantics/forms/the-input-element/email.html
html/semantics/forms/the-input-element/files.html
html/semantics/forms/the-input-element/focus-dynamic-type-change-on-blur.html
html/semantics/forms/the-input-element/focus-dynamic-type-change.html
+7 -3
View File
@@ -875,8 +875,8 @@ impl ElementControlState {
namespace: &str,
local_name: &str,
input_type: InputType,
input_multiple: bool,
input_value_attribute: Option<&str>,
input_multiple: bool,
attribute_name: &str,
attribute_value: Option<&str>,
) {
@@ -924,10 +924,14 @@ impl ElementControlState {
}
}
("input", "multiple") if input_type == InputType::Email => {
let current = self.input_value.as_deref().unwrap_or_default();
let source = if self.input_value_dirty {
self.input_value.as_deref().unwrap_or_default()
} else {
input_value_attribute.unwrap_or_default()
};
self.input_value = Some(sanitize_input_value_for_type_with_multiple(
input_type,
current,
source,
input_multiple,
));
self.input_bad_input = false;
+11 -14
View File
@@ -1163,29 +1163,26 @@ impl Element {
attribute_name: &str,
attribute_value: Option<&str>,
) {
let input_value_attribute = if self.namespace() == "http://www.w3.org/1999/xhtml"
&& self.local_name() == "input"
&& attribute_name == "type"
{
self.attribute("value").map(str::to_owned)
} else {
None
};
let input_type = if self.namespace() == "http://www.w3.org/1999/xhtml"
&& self.local_name() == "input"
&& attribute_name == "type"
{
let is_html_input =
self.namespace() == "http://www.w3.org/1999/xhtml" && self.local_name() == "input";
let input_value_attribute =
if is_html_input && matches!(attribute_name, "type" | "multiple") {
self.attribute("value").map(str::to_owned)
} else {
None
};
let input_type = if is_html_input && attribute_name == "type" {
InputType::from_attribute_value(attribute_value)
} else {
self.input_type()
};
let input_multiple = self.is_html_input() && self.has_attribute("multiple");
let input_multiple = is_html_input && self.has_attribute("multiple");
self.rare_data.sync_control_state_from_attribute(
self.namespace.as_ref(),
self.local_name.as_ref(),
input_type,
input_multiple,
input_value_attribute.as_deref(),
input_multiple,
attribute_name,
attribute_value,
);
+3 -3
View File
@@ -215,8 +215,8 @@ impl ElementRareData {
namespace: &str,
local_name: &str,
input_type: InputType,
input_multiple: bool,
input_value_attribute: Option<&str>,
input_multiple: bool,
attribute_name: &str,
attribute_value: Option<&str>,
) {
@@ -229,8 +229,8 @@ impl ElementRareData {
namespace,
local_name,
input_type,
input_multiple,
input_value_attribute,
input_multiple,
attribute_name,
attribute_value,
);
@@ -250,8 +250,8 @@ impl ElementRareData {
namespace,
local_name,
input_type,
input_multiple,
input_value_attribute,
input_multiple,
attribute_name,
attribute_value,
);
+1
View File
@@ -366,6 +366,7 @@ fn input_type_change_sanitizes_without_dirtying_default_value() {
assert!(input.input_value_dirty());
}
#[test]
fn script_element_state_distinguishes_dynamic_and_parser_created_scripts() {
let dynamic = Element::new_html("script");