From b9e170ccad73a9d57db2d27432b54330090ac30c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sebastian=20Markb=C3=A5ge?= Date: Tue, 22 Aug 2023 19:10:00 -0400 Subject: [PATCH] Fix escaping in action error URL (#27273) This URL is generated on the client (there's an equivalent but shorter SSR version too) when a function is used as an action. It should never happen but it'll be invoked if a form is manually submitted or event is stopped early. The `'` wasn't escaped so this yielded invalid syntax. Which is an error too but much less helpful. `missing ) after argument list`. Added a test that evals to make sure it's correct syntax. --- .../src/client/ReactDOMComponent.js | 2 +- .../src/__tests__/ReactDOMForm-test.js | 47 +++++++++++++++++++ 2 files changed, 48 insertions(+), 1 deletion(-) diff --git a/packages/react-dom-bindings/src/client/ReactDOMComponent.js b/packages/react-dom-bindings/src/client/ReactDOMComponent.js index 6454ee7c2d424..b0f452b29c59e 100644 --- a/packages/react-dom-bindings/src/client/ReactDOMComponent.js +++ b/packages/react-dom-bindings/src/client/ReactDOMComponent.js @@ -501,7 +501,7 @@ function setProp( // eslint-disable-next-line no-script-url "javascript:throw new Error('" + 'A React form was unexpectedly submitted. If you called form.submit() manually, ' + - "consider using form.requestSubmit() instead. If you're trying to use " + + "consider using form.requestSubmit() instead. If you\\'re trying to use " + 'event.stopPropagation() in a submit event handler, consider also calling ' + 'event.preventDefault().' + "')", diff --git a/packages/react-dom/src/__tests__/ReactDOMForm-test.js b/packages/react-dom/src/__tests__/ReactDOMForm-test.js index 50ef3d0212875..2cb2144f532aa 100644 --- a/packages/react-dom/src/__tests__/ReactDOMForm-test.js +++ b/packages/react-dom/src/__tests__/ReactDOMForm-test.js @@ -922,4 +922,51 @@ describe('ReactDOMForm', () => { await act(() => resolveText('Wait')); assertLog(['Async action finished', 'No pending action']); }); + + // @gate enableFormActions + it('should error if submitting a form manually', async () => { + const ref = React.createRef(); + + let error = null; + let result = null; + + function emulateForceSubmit(submitter) { + const form = submitter.form || submitter; + const action = + (submitter && submitter.getAttribute('formaction')) || form.action; + try { + if (!/\s*javascript:/i.test(action)) { + throw new Error('Navigate to: ' + action); + } else { + // eslint-disable-next-line no-new-func + result = Function(action.slice(11))(); + } + } catch (x) { + error = x; + } + } + + const root = ReactDOMClient.createRoot(container); + await act(async () => { + root.render( +
{}} + ref={ref} + onSubmit={e => { + e.preventDefault(); + emulateForceSubmit(e.target); + }}> + +
, + ); + }); + + // This submits the form, which gets blocked and then resubmitted. It's a somewhat + // common idiom but we don't support this pattern unless it uses requestSubmit(). + await submit(ref.current); + expect(result).toBe(null); + expect(error.message).toContain( + 'A React form was unexpectedly submitted. If you called form.submit()', + ); + }); });