A Green API Is Not a Working Page
I spent a morning connecting a session-recording tool to a product search engine I run, expecting to learn something about user behaviour. Instead it handed me a list of JavaScript errors, and every single one turned out to be a bug that had been in production for weeks while every check I had was green.
That is the part worth writing down. Not the bugs — bugs are ordinary. The fact that my entire measurement apparatus was structurally incapable of seeing them.
The one that cost the most
The error text was Unexpected identifier 's'. Twenty-eight occurrences.
The card that renders each product built its click payload like this:
const pJson = JSON.stringify({ id, title, price }) .replace(/'/g, "'") .replace(/"/g, """);return `<a href="${url}"${pJson}')">…</a>`;
That escaping is correct — for an HTML attribute. It is wrong for a JavaScript string, and the attribute is both.
The HTML parser decodes ' back...
Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE