A Green API Is Not a Working Page

https://hackernoon.imgix.net/images/xv85zPaOYqSN3XAN31JUKf7ku8w1-xf83bgw.png

I spent a morning connecting a session-recording tool to a product search engine I run, expecting to learn something about user behaviour. Instead it handed me a list of JavaScript errors, and every single one turned out to be a bug that had been in production for weeks while every check I had was green.

That is the part worth writing down. Not the bugs — bugs are ordinary. The fact that my entire measurement apparatus was structurally incapable of seeing them.

The one that cost the most

The error text was Unexpected identifier 's'. Twenty-eight occurrences.

The card that renders each product built its click payload like this:

const pJson = JSON.stringify({ id, title, price }) .replace(/'/g, "'") .replace(/"/g, """);return `<a href="${url}"${pJson}')">…</a>`;

That escaping is correct — for an HTML attribute. It is wrong for a JavaScript string, and the attribute is both.

The HTML parser decodes ' back...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE

Read more