[ui] IJPL-237218 Introduce safe method for setting tooltip text

`JComponent.setToolTipText` is unsafe because client might be unaware that passed text will be rendered as an HTML. So, it can easily cause accidental HTML injections.
Since we can't modify the source code of JComponent, let's add an extension method for setting the tool tip text using HtmlChunk.

(cherry picked from commit e60607ac4a5a362865ac81df0d7e3cee9d9b064a)

IJ-CR-196509

GitOrigin-RevId: c978d032dbc25061cb654d3ed42a5446654bea55
This commit is contained in:
Konstantin.Hudyakov
2026-03-18 19:25:11 +00:00
committed by intellij-monorepo-bot
parent e2bd94a805
commit 915ae821fe
2 changed files with 19 additions and 0 deletions
+2
View File
@@ -580,6 +580,8 @@ pc:com.intellij.ide.HelpTooltip$OverTipMouseListener
- p:doExit():V
- mouseEntered(java.awt.event.MouseEvent):V
- mouseExited(java.awt.event.MouseEvent):V
f:com.intellij.ide.HelpTooltipKt
- sf:setToolTipText(javax.swing.JComponent,com.intellij.openapi.util.text.HtmlChunk):V
f:com.intellij.ide.IdeBundle
- sf:BUNDLE:java.lang.String
- s:message(java.lang.String,java.lang.Object[]):java.lang.String
@@ -0,0 +1,17 @@
// Copyright 2000-2026 JetBrains s.r.o. and contributors. Use of this source code is governed by the Apache 2.0 license.
package com.intellij.ide
import com.intellij.openapi.util.text.HtmlChunk
import javax.swing.JComponent
/**
* Sets tooltip content.
* Prefer this method over [JComponent.setToolTipText] to avoid accidental HTML injections.
*
* Tooltip text is allowed to contain HTML markup. Construct the text using [HtmlChunk].
* If your tooltip doesn't suppose to contain HTML markup,
* prefer using [HtmlChunk.text] to avoid accidental HTML injections.
*/
fun JComponent.setToolTipText(html: HtmlChunk?) {
this.toolTipText = html?.toString()
}