fix(catalog): decode and strip stray markup from product descriptions

P0-5: some catalog listings (live backend data, proxied third-party
marketplace via novo.market) carry HTML-entity-encoded markup in
their description field, e.g. '<attention>...</attention>'
and '"AppStops"' — rendered verbatim as visible text on
search-result cards and the PDP description tab.

Added a pure cleanDescription() util (item.utils.ts) that decodes
the common HTML entities and strips any resulting tag-like markup,
then wired it into ProductCardComponent (covers Home/Catalog/Search/
Wishlist/Compare/PDP-similar) and ProductDescriptionComponent (PDP
description tab). Output stays a plain string rendered via text
interpolation (never innerHTML), so this only cleans up display —
it introduces no HTML-rendering/XSS surface.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
sdarbinyan
2026-07-19 22:56:12 +04:00
parent 374774901e
commit a39b3429ba
5 changed files with 32 additions and 4 deletions

View File

@@ -2,8 +2,8 @@
<h2>{{ 'itemDetail.description' | translate }}</h2>
@if (simpleDescription) {
<p>{{ simpleDescription }}</p>
<p>{{ cleanDescription(simpleDescription) }}</p>
} @else if (product.description) {
<p>{{ product.description }}</p>
<p>{{ cleanDescription(product.description) }}</p>
}
</section>

View File

@@ -1,6 +1,7 @@
import { ChangeDetectionStrategy, Component, Input } from '@angular/core';
import { Product } from '../../../../../core/products/models/product-domain.model';
import { TranslatePipe } from '../../../../../i18n/translate.pipe';
import { cleanDescription } from '../../../../../utils/item.utils';
@Component({
selector: 'app-product-description',
@@ -13,4 +14,6 @@ import { TranslatePipe } from '../../../../../i18n/translate.pipe';
export class ProductDescriptionComponent {
@Input({ required: true }) product!: Product;
@Input() simpleDescription = '';
readonly cleanDescription = cleanDescription;
}