Skip to content

fix: reject invalid hex and merge tokens in color sanitize - #212

Merged
dazzatronus merged 1 commit into
mainfrom
fix/sanitize-bad-hex-and-merge-color-tokens
Sep 29, 2026
Merged

dazzatronus merged 1 commit into
mainfrom
fix/sanitize-bad-hex-and-merge-color-tokens

Conversation

@dazzatronus

Copy link
Copy Markdown
Contributor

Summary

  • Fix sanitizeColor hex matching so only Pixi-valid lengths (3/4/6/8) pass — 5-digit values like #00000 previously slipped through and crashed TextStyle / Color.
  • Fall back for unsubstituted merge tokens such as {{ BG_COLOR }}.
  • Sanitize timeline background at Graphics fillStyle (init + viewport update) so invalid document backgrounds no longer throw.

Test plan

  • Unit: #00000, #12345, {{ BG_COLOR }} fall back; valid 3/4/6/8 hex preserved
  • Full jest suite green
  • Vite: load a template with text font.color: "#00000" and timeline background: "{{ BG_COLOR }}"; confirm studio loads with no Pixi convert-color crash

The prior HEX_PATTERN treated 5-digit values like #00000 as valid, so
they still reached Pixi Color and threw. Align with Pixi's 3/4/6/8 rule,
cover unsubstituted {{ VAR }} tokens, and sanitize timeline background
fills before Graphics fillStyle.
@dazzatronus
dazzatronus merged commit 5874685 into main Sep 29, 2026
1 check passed
github-actions Bot pushed a commit that referenced this pull request Sep 29, 2026
## [2.23.2](v2.23.1...v2.23.2) (2026-09-29)

### Bug Fixes

* reject invalid hex and merge tokens in color sanitize ([#212](#212)) ([5874685](5874685)), closes [#00000](https://github.com/shotstack/shotstack-studio-sdk/issues/00000)
@github-actions

Copy link
Copy Markdown

🎉 This PR is included in version 2.23.2 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant