Fix CurrencyInputProps leaking into underlying <input> element via customProps spread - #49
Conversation
|
There is no change log for this pull request yet. |
… input element Co-authored-by: ericblade <1451847+ericblade@users.noreply.github.com>
<input> element via customProps spread
|
@copilot is there some way we can take advantage of typescript to make it so that anything added to CurrencyInputProps but not handled in prepareProps() will throw an error or warning? |
…handled in prepareProps Co-authored-by: ericblade <1451847+ericblade@users.noreply.github.com>
Yes — added an exhaustive check using TypeScript's type system in const _: Record<keyof Required<CurrencyInputProps>, unknown> = {
onBlur, onClick, onFocus, onChangeEvent,
allowEmpty, allowNegative, autoFocus,
disableSelectionHandling: propDisableSelectionHandling, selectAllOnFocus,
decimalSeparator, inputType, precision, prefix, style, suffix, thousandSeparator,
id, tabIndex, value: propValue,
logValues,
};
void _;
|
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The changes directly address the prop-leakage issue by removing known component props from customProps and add a compile-time guard to prevent regressions.
Review effort: Lite
Findings: None
What changed in this PR
This PR prevents CurrencyInputProps-specific fields from being forwarded to the underlying <input> via the customProps rest spread, addressing the reported logValues leak (and related prop leakage concerns) from issue #48.
Changes:
- Updated
preparePropsdestructuring to explicitly pull out additional knownCurrencyInputPropsfields (onBlur,onClick,onFocus,style,id,tabIndex,logValues) so they don’t end up incustomProps. - Added a TypeScript “exhaustiveness” check intended to fail compilation if
CurrencyInputPropsgains a new key that isn’t accounted for inprepareProps.
| File | Description |
|---|---|
| src/index.tsx | Ensures CurrencyInputProps fields don’t leak into <input> attributes via customProps, and adds a TS exhaustiveness guard. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
preparePropsdidn't destructure allCurrencyInputPropsfields before the...customPropsrest spread, causing props likelogValues,onBlur,onClick,onFocus,style,id, andtabIndexto be forwarded as raw HTML attributes on the<input>element.Changes
preparePropsdestructuring — Added the missingCurrencyInputPropsfields to the destructuring so they are stripped fromcustomPropsbefore it is spread onto<input>:logValues— primary reported culpritonBlur,onClick,onFocus— already wired up explicitly in render/handlers, but were also leaking throughcustomProps, causing duplicate/conflicting event handler bindingsstyle,id,tabIndex— same pattern; already set explicitly in renderAfter this change,
customPropsonly contains genuinely "extra" HTML attributes consumers intend for the underlying<input>(e.g.data-*,aria-*,name,placeholder).