Skip to content

Maintenance: fix variation generation bugs, validation, UX/a11y and SheetJS upgrade - #1

Merged
fadyehabamer merged 11 commits into
mainfrom
maintenance/2026-09
Sep 24, 2026
Merged

fadyehabamer merged 11 commits into
mainfrom
maintenance/2026-09

Conversation

@fadyehabamer

Copy link
Copy Markdown
Owner

Summary

Core logic (generateEmailVariations)

  • Consecutive dots. Existing dots were combined with inserted ones: john.doe@gmail.com gave 96 results, and 64 of them contained .., which makes them invalid. Existing dots are now removed first, which gives the correct 64 unique variations.
  • +tag handling. Dots were being inserted inside and around the +tag, for example ab.+n.e.w.s@gmail.com. Only the username before + is varied now.
  • Exponential blow-up. The count is 2^(n-1): a 20-character username rendered 524,288 cells, and longer ones never finished. Output is now capped at 8,192 (every variation for usernames up to 14 characters), and a status message reports the total when the list is truncated.

Validation

  • Now accepts a+b@gmail.com and long TLDs like x@example.photography.
  • Now rejects a..b@, .ab@, ab.@, a@b..com and a@-b.com.

UX / a11y / HTML

  • After one run the input was disabled and re-submitting showed an "already generated" alert, so the page had to be reloaded to try another address. That is fixed. Export now writes exactly the list shown instead of re-reading the input.
  • Validation errors appear inline in the #errorMsg element (previously unused), which has role="alert". The input gets aria-invalid and is linked with aria-describedby. There is also a role="status" message.
  • Pressing Enter now generates: the controls are wrapped in a novalidate form.
  • Fixed the <h2>…</h3> mismatch. The page now has a single h1, and the attribution line is a paragraph.
  • Added a meta description.

Dependencies

  • SheetJS upgraded from 0.17.0 (cdnjs) to 0.20.3 (the official cdn.sheetjs.com). cdnjs stops at 0.18.5, and versions before 0.20.2 are affected by CVE-2023-30533 and CVE-2024-22363. Both affect parsing, not the write-only use here, but this moves the app off known-vulnerable code.

Docs

  • README now explains how variations work, the Gmail-only caveat, the limits, how to run it locally and the license.

Verification

  • node --check main.js passes.
  • Node harness for generateEmailVariations and countEmailVariations:
    • abc gives 4, john.doe gives 64, ab+news gives 2, a 14-character username gives 8192/8192, a 15-character one gives 8192/16384, and a 64-character one finishes in about 5 ms.
    • Every output is unique, has no .., and passes the new validator.
  • Validator: 19 accept/reject cases, 0 failures. Pathological 20k-character inputs finish in under 1 ms, so no ReDoS.
  • DOM-stub harness for generateAndDisplayVariations:
    • An invalid input shows the inline error and sets aria-invalid.
    • A valid input fills 22 rows (64 cells) and enables export.
    • A second email works without a reload.
    • A long username shows the truncation status.
  • Export harness: ran exportToExcel() against SheetJS 0.20.3 in Node. It produced email_variations.xlsx with sheet EmailVariations, and reading it back gave a header plus 64 rows.
  • curl: the SheetJS 0.20.3 CDN URL returns 200, application/javascript, with CORS *. fadyehabamer.com and the Vercel demo return 200.
  • Every element ID used in main.js exists in index.html. CRLF line endings are preserved.
  • Not checked in a browser. The visual result still needs a quick look.

"john.doe@gmail.com" produced 96 results of which 64 contained ".."
(invalid addresses). Existing dots are now removed before generating,
giving the correct 64 distinct variations.
Previously dots were inserted around and inside the "+tag" part
(e.g. "ab.+n.e.w.s@gmail.com"); only the username before "+" is
dot-insensitive in Gmail.
…ation

The old pattern rejected valid addresses such as "a+b@gmail.com" and
"x@example.photography" while accepting invalid ones like
"a..b@gmail.com", ".ab@gmail.com" and "a@b..com".
After the first run the input was disabled and re-submitting showed an
"already generated" alert, so the page had to be reloaded to try
another address. The export also re-read the input instead of using the
list shown. The displayed email/variations are now kept in state and
exported as-is.
…alert()

Uses the previously unused #errorMsg element with role="alert", marks
the input aria-invalid and links it via aria-describedby.
The count doubles with each username character (2^(n-1)); a 20-char
username produced 524,288 table cells and longer ones never finished.
Output is now capped at 8192 (all variations for usernames up to 14
characters) and a status message reports the total when truncated.
The subtitle opened with <h2> but closed with </h3>, and the page had no
h1. The title is now the h1 and the attribution line a paragraph.
Wraps the input and buttons in a form (novalidate, so the app's own
validation message is used) with the generate button as its submit.
SheetJS no longer publishes to npm/cdnjs (cdnjs stops at 0.18.5), and
versions before 0.20.2 carry CVE-2023-30533 and CVE-2024-22363. Those
affect parsing rather than the write-only use here, but staying on a
maintained release avoids shipping known-vulnerable code. Export was
verified in Node: book_new/aoa_to_sheet/book_append_sheet/write produce
the same sheet (header + 64 rows for john.doe@gmail.com).
Copilot AI lite review requested due to automatic review settings September 24, 2026 11:51
@vercel

vercel Bot commented Sep 24, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
fea-email-variations-generator Error Error Sep 24, 2026 11:51am UTC

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Fix the variation-count overflow that can report Infinity for long valid usernames.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
What changed in this PR

This PR fixes email variation generation, validation, accessibility, export behavior, documentation, and the SheetJS dependency.

Changes:

  • Handles dots and +tags correctly while capping output.
  • Improves validation, inline feedback, form submission, and accessibility.
  • Updates HTML, styling, documentation, and SheetJS.
File Description
style.css Updated heading and validation-message styling
README.md Added usage, limitations, setup, and license documentation
main.js Updated generation, validation, display, and export logic; count calculation can overflow to Infinity for sufficiently long valid usernames
index.html Improved form accessibility, metadata, semantics, and dependency inclusion

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread main.js
// Total number of dot variations for an email (may exceed MAX_VARIATIONS).
function countEmailVariations(email) {
let localPart = email.split("@")[0].split("+")[0].replace(/\./g, "");
return 2 ** Math.max(localPart.length - 1, 0);
@fadyehabamer
fadyehabamer merged commit e355643 into main Sep 24, 2026
2 of 3 checks passed
@fadyehabamer
fadyehabamer deleted the maintenance/2026-09 branch September 24, 2026 13:00

This branch had an error being deployed

1 failed deployment
Preview — f5600764 Deployed Sep 24, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants