ec27228a8e
Em dashes (—) and en dashes (–) had spread across comments, docs, tests, and a few UI strings, reading as AI-generated boilerplate rather than house style. Replaced each with punctuation matching its context: colon for explanatory clauses, comma for asides, plain hyphen for numeric/legal ranges (e.g. "21-23§"), "to"/"till" for date ranges, parentheses for paired-dash asides. messages/en.json and messages/sv.json were fixed by hand together to keep sv/en in sync. Left untouched where the dash is the functional subject rather than decorative punctuation: date-range-parser.ts's separator regex, charset-repair.ts's CP1252 byte-mapping table (and its test), the SIE encoding mojibake docs, generic-csv.ts's minus-sign normalizer, the agent system-prompt files that already instruct against em dashes, and a golden iXBRL test fixture compared byte-for-byte. Also fixes two bugs surfaced along the way: an off-by-one in ApiKeysPanel's scope-label split (a leftover from an earlier partial pass), and a charset-repair test that had lost the literal en-dash it exists to verify. Regenerated the agent atom seed migration (skills:generate) since 27 SKILL.md files changed. Added a CLAUDE.md rule against em/en dashes, with an explicit carve-out for the functional-dash cases above. Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
42 lines
1.5 KiB
TypeScript
42 lines
1.5 KiB
TypeScript
/**
|
|
* Utilities for safely rendering user-authored text in outgoing emails.
|
|
*
|
|
* Company-editable email texts (see company_settings.invoice_email_texts)
|
|
* are untrusted input: they must be escaped before interpolation into HTML
|
|
* templates and kept single-line when used as mail headers.
|
|
*/
|
|
|
|
export function escapeHtml(input: string): string {
|
|
return input
|
|
.replace(/&/g, '&')
|
|
.replace(/</g, '<')
|
|
.replace(/>/g, '>')
|
|
.replace(/"/g, '"')
|
|
.replace(/'/g, ''')
|
|
}
|
|
|
|
// Escape FIRST, then convert newlines, order matters: a '<br>' typed by the
|
|
// user must arrive escaped; only OUR <br> survives.
|
|
export function userTextToHtml(input: string): string {
|
|
return escapeHtml(input).replace(/\r\n|\r|\n/g, '<br>')
|
|
}
|
|
|
|
// Mail-header hygiene: a subject must be a single line (header injection).
|
|
export function sanitizeSubjectLine(input: string): string {
|
|
return input.replace(/[\r\n]+/g, ' ').trim()
|
|
}
|
|
|
|
// Fixed-set {x} substitution. Single pass: substituted VALUES are never
|
|
// re-scanned, so a customer named '{belopp}' stays literal. Unknown keys are
|
|
// left as-is so the user sees and fixes typos. Keys are matched after
|
|
// trim + toLowerCase (forgiving of '{ Förnamn }').
|
|
export function applyPlaceholders(
|
|
template: string,
|
|
values: Record<string, string>,
|
|
): string {
|
|
return template.replace(/\{([^{}]*)\}/g, (match, rawKey: string) => {
|
|
const value = values[rawKey.trim().toLowerCase()]
|
|
return value !== undefined ? value : match
|
|
})
|
|
}
|