Don't extract links as arbitrary properties (#17129)

Closes #17128

This PR prevents extraction of links inside square brackets as valid
candidate:

```
[https://example/]
```

We do this by throwing out arbitrary properties when the value starts
with a slash (`/`).

## Test plan

- Added unit test

---------

Co-authored-by: Robin Malfait <malfait.robin@gmail.com>
This commit is contained in:
Philipp Spiess 2025-03-11 17:40:24 +01:00 • committed by GitHub
parent 785cadeb21
commit 9d7f25316e
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 11 additions and 0 deletions

View file

@ -24,6 +24,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
- Treat starting single quote as verbatim text in Slim ([#17085](https://github.com/tailwindlabs/tailwindcss/pull/17085))
- Ensure `.node` and `.wasm` files are not scanned for utilities ([#17123](https://github.com/tailwindlabs/tailwindcss/pull/17123))
- Improve performance when scanning `JSON` files ([#17125](https://github.com/tailwindlabs/tailwindcss/pull/17125))
- Don't create invalid CSS when encountering a link wrapped in square brackets ([#17129](https://github.com/tailwindlabs/tailwindcss/pull/17129))
## [4.0.12] - 2025-03-07

View file

@ -163,6 +163,7 @@ impl Machine for ArbitraryPropertyMachine<ParsingValueState> {
#[inline]
fn next(&mut self, cursor: &mut cursor::Cursor<'_>) -> MachineState {
let len = cursor.input.len();
let start_of_value_pos = cursor.pos;
while cursor.pos < len {
match cursor.curr.into() {
Class::Escape => match cursor.next.into() {
@ -222,6 +223,9 @@ impl Machine for ArbitraryPropertyMachine<ParsingValueState> {
// Any kind of whitespace is not allowed
Class::Whitespace => return self.restart(),
// URLs are not allowed
Class::Slash if start_of_value_pos == cursor.pos => return self.restart(),
// Everything else is valid
_ => cursor.advance(),
};
@ -278,6 +282,9 @@ enum Class {
#[bytes(b':')]
Colon,
#[bytes(b'/')]
Slash,
#[bytes(b' ', b'\t', b'\n', b'\r', b'\x0C')]
Whitespace,
@ -341,6 +348,9 @@ mod tests {
("[:red]", vec![]),
// Empty brackets are not allowed
("[]", vec![]),
// URLs
("[http://example.com]", vec![]),
("[https://example.com]", vec![]),
// Missing colon in more complex example
(r#"[CssClass("gap-y-4")]"#, vec![]),
// Brackets must be balanced