bhaskargurram-ai opened a new pull request, #708:
URL: https://github.com/apache/shenyu-dashboard/pull/708

   Fixes #614
   
   ## What is the problem
   
   When an API debug response is not JSON, `ApiDebug.js` passed the upstream 
body to `ReactHtmlParser(responseInfo.body)`. Markup returned by the gateway, 
such as styles, forms, images or other embedded content, then became live 
elements inside the dashboard.
   
   ## What this PR does
   
   - Shows non-JSON response bodies as text inside a `<pre>` (`white-space: 
pre-wrap`, `word-wrap: break-word`, the same styling `ImportResultModal` uses). 
React escapes the text, so markup appears literally and no DOM elements are 
created from it. JSON bodies are still shown with `ReactJson`, and an empty 
body still shows `Empty`.
   - `react-html-parser` had no other users, so this removes it from 
`package.json`. `package-lock.json` is updated with `npm uninstall 
--package-lock-only`. That removed the `react-html-parser` tree and marked four 
transitive packages it alone pulled into production (`inherits`, `safe-buffer`, 
`string_decoder`, `util-deprecate`) as `dev: true`. Running `npm install 
--package-lock-only` again leaves the lockfile unchanged.
   - Removes the now-unneeded `jest.mock("react-html-parser")` from 
`ApiDebug.state.test.js`.
   
   ## How I tested it
   
   - New test in `ApiDebug.test.js`: it submits a request whose response body 
is `<img id="injected" src="x"><b>upstream</b>\n  <form id="fake"></form>`. It 
checks that the `<pre>` text equals the raw body, the `<pre>` has no child 
elements, and no `#injected` or `#fake` element exists. Against the old 
`ReactHtmlParser` rendering, the test fails.
   - `npx jest --runInBand`: 52 suites, 249 tests passed. I ran this with 
`node_modules/react-html-parser` moved away to confirm nothing still needs the 
package.
   - `npm run build` (roadhog) compiled successfully with `react-html-parser` 
absent from `node_modules`.
   - `eslint` and `prettier --check` pass on the changed files.
   
   ## Checklist
   
   - [x] Test added
   - [x] `npm run test:unit` passes locally
   - [x] `npm run build` passes locally
   - [x] ESLint / Prettier clean on changed files
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to