mirror of
https://gitflic.ru/project/openide/openide.git
synced 2026-09-27 10:03:11 +07:00
[ui] IJPL-237218 Introduce safe method for setting tooltip text
`JComponent.setToolTipText` is unsafe because client might be unaware that passed text will be rendered as an HTML. So, it can easily cause accidental HTML injections. Since we can't modify the source code of JComponent, let's add an extension method for setting the tool tip text using HtmlChunk. (cherry picked from commit e60607ac4a5a362865ac81df0d7e3cee9d9b064a) IJ-CR-196509 GitOrigin-RevId: c978d032dbc25061cb654d3ed42a5446654bea55
This commit is contained in:
committed by
intellij-monorepo-bot
parent
e2bd94a805
commit
915ae821fe
@@ -580,6 +580,8 @@ pc:com.intellij.ide.HelpTooltip$OverTipMouseListener
|
||||
- p:doExit():V
|
||||
- mouseEntered(java.awt.event.MouseEvent):V
|
||||
- mouseExited(java.awt.event.MouseEvent):V
|
||||
f:com.intellij.ide.HelpTooltipKt
|
||||
- sf:setToolTipText(javax.swing.JComponent,com.intellij.openapi.util.text.HtmlChunk):V
|
||||
f:com.intellij.ide.IdeBundle
|
||||
- sf:BUNDLE:java.lang.String
|
||||
- s:message(java.lang.String,java.lang.Object[]):java.lang.String
|
||||
|
||||
@@ -0,0 +1,17 @@
|
||||
// Copyright 2000-2026 JetBrains s.r.o. and contributors. Use of this source code is governed by the Apache 2.0 license.
|
||||
package com.intellij.ide
|
||||
|
||||
import com.intellij.openapi.util.text.HtmlChunk
|
||||
import javax.swing.JComponent
|
||||
|
||||
/**
|
||||
* Sets tooltip content.
|
||||
* Prefer this method over [JComponent.setToolTipText] to avoid accidental HTML injections.
|
||||
*
|
||||
* Tooltip text is allowed to contain HTML markup. Construct the text using [HtmlChunk].
|
||||
* If your tooltip doesn't suppose to contain HTML markup,
|
||||
* prefer using [HtmlChunk.text] to avoid accidental HTML injections.
|
||||
*/
|
||||
fun JComponent.setToolTipText(html: HtmlChunk?) {
|
||||
this.toolTipText = html?.toString()
|
||||
}
|
||||
Reference in New Issue
Block a user