Skip to content

fix(isISO8601): only accept T or a space as the date-time separator - #2892

Open
yu2971512385-ui wants to merge 1 commit into
validatorjs:masterfrom
yu2971512385-ui:fix/isISO8601-separator
Open

yu2971512385-ui wants to merge 1 commit into
validatorjs:masterfrom
yu2971512385-ui:fix/isISO8601-separator

Conversation

@yu2971512385-ui

Copy link
Copy Markdown

Fixes #2861.

The bug

The default pattern separates the date and time with [T\s]:

const iso8601 = /.../([T\s](...time...))?.../;

\s matches tab, newline, form feed, vertical tab and a non-breaking space in addition to a plain space, so all of them are accepted as ISO 8601 separators:

validator.isISO8601('2009-01-01\t00:00:00'); // true (tab)
validator.isISO8601('2009-01-01\n00:00:00'); // true (newline)
validator.isISO8601('2009-01-01\f00:00:00'); // true (form feed)
validator.isISO8601('2009-01-01\v00:00:00'); // true (vertical tab)

ISO 8601 permits only T; RFC 3339 §5.6 additionally allows a plain space (which is why the class accepts a space). No relevant specification allows the rest of \s. Accepting a newline is particularly undesirable, since it lets a two-line input pass a single-value check.

The fix

Narrow the class in the default pattern to [T ]. strictSeparator: true already uses [T] and is unchanged; the plain-space separator that RFC 3339 allows (e.g. 2009-05-19 14:39:22) keeps working.

Tests

Added a case asserting T and a space are accepted while tab, newline, form feed, vertical tab and a non-breaking space are rejected. Verified it fails on the unpatched source and passes with the fix; full npm test is green.

Checklist

  • PR contains only changes related; no stray files, etc.
  • README updated (where applicable)
  • Tests written (where applicable)
  • References provided in PR (where applicable)

🤖 Generated with Claude Code

The default pattern separated the date and time with `[T\s]`, so tab, newline,
form feed, vertical tab and a non-breaking space were all accepted as
separators. ISO 8601 permits only `T`, and RFC 3339 §5.6 additionally allows a
plain space — no specification allows the rest of `\s`. Accepting a newline is
particularly undesirable since it lets a two-line input pass a single-value
check.

Narrow the class to `[T ]`. `strictSeparator: true` (which already uses `[T]`)
is unchanged.

Fixes validatorjs#2861

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@codecov

codecov Bot commented Sep 17, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (9ff3424) to head (3001b3a).

Additional details and impacted files
@@            Coverage Diff            @@
##            master     #2892   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files          114       114           
  Lines         2599      2599           
  Branches       658       658           
=========================================
  Hits          2599      2599           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

isISO8601 accepts any whitespace as the date-time separator

1 participant