Copilot commented on code in PR #44907:
URL: https://github.com/apache/superset/pull/44907#discussion_r4172276380


##########
superset-frontend/plugins/plugin-chart-ag-grid-table/src/renderers/TextCellRenderer.tsx:
##########
@@ -51,6 +61,24 @@ export const TextCellRenderer = (params: CellRendererProps) 
=> {
     }
   }
 
+  // Object and array JSON is interactive. Plain text, URLs, and opt-in HTML
+  // stay on the paths below.
+  const parsedJson = parseJsonCellValue(value);
+  if (parsedJson) {

Review Comment:
   JSON detection runs before the existing opt-in HTML branch, so valid 
object/array text containing an HTML tag (for example, 
`{"message":"<b>ok</b>"}`) is now rendered as JSON instead of through the 
sanitized HTML renderer. Since `allowRenderHtml` defaults to true, this 
regresses the stated guarantee that HTML cells remain unchanged; exclude values 
recognized by the enabled HTML path from JSON rendering.



##########
superset-frontend/plugins/plugin-chart-ag-grid-table/src/renderers/parseJsonCellValue.ts:
##########
@@ -0,0 +1,175 @@
+/**
+ * Licensed to the Apache Software Foundation (ASF) under one
+ * or more contributor license agreements.  See the NOTICE file
+ * distributed with this work for additional information
+ * regarding copyright ownership.  The ASF licenses this file
+ * to you under the Apache License, Version 2.0 (the
+ * "License"); you may not use this file except in compliance
+ * with the License.  You may obtain a copy of the License at
+ *
+ *   http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing,
+ * software distributed under the License is distributed on an
+ * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+ * KIND, either express or implied.  See the License for the
+ * specific language governing permissions and limitations
+ * under the License.
+ */
+
+export type JsonContainer = Record<string, unknown> | unknown[];
+
+// Visible cells are parsed on the render path. Above this size the cell stays
+// plain text. Parsed results are reused for the same string.
+const MAX_JSON_CELL_LENGTH = 100_000;
+const PARSE_CACHE_LIMIT = 200;
+
+const parsedJsonCache = new Map<string, JsonContainer | null>();
+
+function isJsonContainer(value: unknown): value is JsonContainer {
+  if (value === null || typeof value !== 'object') {
+    return false;
+  }
+  if (Array.isArray(value)) {
+    return true;
+  }
+  if (value instanceof Date) {
+    return false;
+  }
+  const prototype = Object.getPrototypeOf(value);
+  return prototype === Object.prototype || prototype === null;
+}
+
+function isPlainJsonObject(value: unknown): value is Record<string, unknown> {
+  return isJsonContainer(value) && !Array.isArray(value);
+}
+
+function rememberParse(
+  text: string,
+  parsed: JsonContainer | null,
+): JsonContainer | null {
+  if (parsedJsonCache.size >= PARSE_CACHE_LIMIT) {
+    const oldest = parsedJsonCache.keys().next().value;
+    if (oldest !== undefined) {
+      parsedJsonCache.delete(oldest);
+    }
+  }
+  parsedJsonCache.set(text, parsed);
+  return parsed;
+}
+
+/**
+ * Accept a JSON object or array, either already parsed or as text.
+ * Scalars, invalid JSON, and non-JSON text return null so the cell stays
+ * on the plain-text renderer.
+ */
+export function parseJsonCellValue(value: unknown): JsonContainer | null {
+  if (isJsonContainer(value)) {
+    return value;
+  }
+  if (typeof value !== 'string') {
+    return null;
+  }
+  const trimmed = value.trim();
+  if (
+    trimmed.length === 0 ||
+    trimmed.length > MAX_JSON_CELL_LENGTH ||

Review Comment:
   The 100 KB guard is applied after trimming, so an input whose total text is 
oversized but mostly leading/trailing whitespace still becomes an interactive 
JSON cell (for example, 100,001 spaces followed by `{}`). This contradicts the 
documented size limit and still makes the preview/copy paths process the 
oversized original text. Check the original string length instead.



##########
superset-frontend/plugins/plugin-chart-ag-grid-table/src/renderers/parseJsonCellValue.ts:
##########
@@ -0,0 +1,175 @@
+/**
+ * Licensed to the Apache Software Foundation (ASF) under one
+ * or more contributor license agreements.  See the NOTICE file
+ * distributed with this work for additional information
+ * regarding copyright ownership.  The ASF licenses this file
+ * to you under the Apache License, Version 2.0 (the
+ * "License"); you may not use this file except in compliance
+ * with the License.  You may obtain a copy of the License at
+ *
+ *   http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing,
+ * software distributed under the License is distributed on an
+ * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+ * KIND, either express or implied.  See the License for the
+ * specific language governing permissions and limitations
+ * under the License.
+ */
+
+export type JsonContainer = Record<string, unknown> | unknown[];
+
+// Visible cells are parsed on the render path. Above this size the cell stays
+// plain text. Parsed results are reused for the same string.
+const MAX_JSON_CELL_LENGTH = 100_000;
+const PARSE_CACHE_LIMIT = 200;
+
+const parsedJsonCache = new Map<string, JsonContainer | null>();
+
+function isJsonContainer(value: unknown): value is JsonContainer {
+  if (value === null || typeof value !== 'object') {
+    return false;
+  }
+  if (Array.isArray(value)) {
+    return true;
+  }
+  if (value instanceof Date) {
+    return false;
+  }
+  const prototype = Object.getPrototypeOf(value);
+  return prototype === Object.prototype || prototype === null;
+}
+
+function isPlainJsonObject(value: unknown): value is Record<string, unknown> {
+  return isJsonContainer(value) && !Array.isArray(value);
+}
+
+function rememberParse(
+  text: string,
+  parsed: JsonContainer | null,
+): JsonContainer | null {
+  if (parsedJsonCache.size >= PARSE_CACHE_LIMIT) {
+    const oldest = parsedJsonCache.keys().next().value;
+    if (oldest !== undefined) {
+      parsedJsonCache.delete(oldest);
+    }
+  }
+  parsedJsonCache.set(text, parsed);
+  return parsed;
+}
+
+/**
+ * Accept a JSON object or array, either already parsed or as text.
+ * Scalars, invalid JSON, and non-JSON text return null so the cell stays
+ * on the plain-text renderer.
+ */
+export function parseJsonCellValue(value: unknown): JsonContainer | null {
+  if (isJsonContainer(value)) {
+    return value;
+  }
+  if (typeof value !== 'string') {
+    return null;
+  }
+  const trimmed = value.trim();
+  if (
+    trimmed.length === 0 ||
+    trimmed.length > MAX_JSON_CELL_LENGTH ||
+    (trimmed[0] !== '{' && trimmed[0] !== '[')
+  ) {
+    return null;
+  }
+  const cached = parsedJsonCache.get(trimmed);
+  if (cached !== undefined) {
+    return cached;
+  }
+  try {
+    const parsed: unknown = JSON.parse(trimmed);
+    return rememberParse(trimmed, isJsonContainer(parsed) ? parsed : null);
+  } catch {
+    return rememberParse(trimmed, null);
+  }
+}
+
+function isFormattingWhitespace(char: string): boolean {
+  return char === ' ' || char === '\n' || char === '\r' || char === '\t';
+}
+
+/**
+ * Collapse formatting whitespace onto one line. Spaces inside JSON strings
+ * stay as written.
+ */
+function collapseFormattingWhitespace(source: string): string {
+  let collapsed = '';
+  let inString = false;
+  let escaped = false;
+  let pendingSpace = false;
+
+  for (let index = 0; index < source.length; index += 1) {
+    const char = source[index];
+    if (inString) {
+      collapsed += char;
+      if (escaped) {
+        escaped = false;
+      } else if (char === '\\') {
+        escaped = true;
+      } else if (char === '"') {
+        inString = false;
+      }
+      continue;
+    }
+    if (isFormattingWhitespace(char)) {
+      pendingSpace = collapsed.length > 0;
+      continue;
+    }
+    if (char === '"') {
+      inString = true;
+    }
+    if (pendingSpace) {
+      collapsed += ' ';
+      pendingSpace = false;
+    }
+    collapsed += char;
+  }
+  return collapsed.trim();
+}
+
+function exceedsPreviewBudget(
+  value: unknown,
+  budget: { left: number },
+): boolean {
+  if (budget.left < 0) {
+    return true;
+  }
+  if (typeof value === 'string') {
+    budget.left -= value.length;
+    return budget.left < 0;
+  }
+  if (Array.isArray(value)) {
+    budget.left -= value.length;
+    return value.some(item => exceedsPreviewBudget(item, budget));
+  }
+  if (isPlainJsonObject(value)) {
+    const keys = Object.keys(value);
+    budget.left -= keys.length;
+    return keys.some(key => exceedsPreviewBudget(value[key], budget));
+  }
+  return false;
+}

Review Comment:
   This recursive traversal can overflow the JavaScript call stack before the 
guarded `JSON.stringify` runs. A valid sub-100-KB value with sufficiently deep 
nesting (for example, 20,000 nested arrays) parses successfully but throws 
`RangeError` here and crashes cell rendering. Traverse with an explicit stack 
(and guard repeated object references for already-parsed inputs) so 
pathological data falls back to the abbreviated preview.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to