Repository navigation
Maintenance: fix variation generation bugs, validation, UX/a11y and SheetJS upgrade - #1
Merged
Merged
Conversation
"john.doe@gmail.com" produced 96 results of which 64 contained ".." (invalid addresses). Existing dots are now removed before generating, giving the correct 64 distinct variations.
Previously dots were inserted around and inside the "+tag" part (e.g. "ab.+n.e.w.s@gmail.com"); only the username before "+" is dot-insensitive in Gmail.
…ation The old pattern rejected valid addresses such as "a+b@gmail.com" and "x@example.photography" while accepting invalid ones like "a..b@gmail.com", ".ab@gmail.com" and "a@b..com".
After the first run the input was disabled and re-submitting showed an "already generated" alert, so the page had to be reloaded to try another address. The export also re-read the input instead of using the list shown. The displayed email/variations are now kept in state and exported as-is.
…alert() Uses the previously unused #errorMsg element with role="alert", marks the input aria-invalid and links it via aria-describedby.
The count doubles with each username character (2^(n-1)); a 20-char username produced 524,288 table cells and longer ones never finished. Output is now capped at 8192 (all variations for usernames up to 14 characters) and a status message reports the total when truncated.
The subtitle opened with <h2> but closed with </h3>, and the page had no h1. The title is now the h1 and the attribution line a paragraph.
Wraps the input and buttons in a form (novalidate, so the app's own validation message is used) with the generate button as its submit.
SheetJS no longer publishes to npm/cdnjs (cdnjs stops at 0.18.5), and versions before 0.20.2 carry CVE-2023-30533 and CVE-2024-22363. Those affect parsing rather than the write-only use here, but staying on a maintained release avoids shipping known-vulnerable code. Export was verified in Node: book_new/aoa_to_sheet/book_append_sheet/write produce the same sheet (header + 64 rows for john.doe@gmail.com).
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Fix the variation-count overflow that can report Infinity for long valid usernames.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
This PR fixes email variation generation, validation, accessibility, export behavior, documentation, and the SheetJS dependency.
Changes:
- Handles dots and
+tagscorrectly while capping output. - Improves validation, inline feedback, form submission, and accessibility.
- Updates HTML, styling, documentation, and SheetJS.
| File | Description |
|---|---|
style.css |
Updated heading and validation-message styling |
README.md |
Added usage, limitations, setup, and license documentation |
main.js |
Updated generation, validation, display, and export logic; count calculation can overflow to Infinity for sufficiently long valid usernames |
index.html |
Improved form accessibility, metadata, semantics, and dependency inclusion |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| // Total number of dot variations for an email (may exceed MAX_VARIATIONS). | ||
| function countEmailVariations(email) { | ||
| let localPart = email.split("@")[0].split("+")[0].replace(/\./g, ""); | ||
| return 2 ** Math.max(localPart.length - 1, 0); |
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
Core logic (
generateEmailVariations)john.doe@gmail.comgave 96 results, and 64 of them contained.., which makes them invalid. Existing dots are now removed first, which gives the correct 64 unique variations.+taghandling. Dots were being inserted inside and around the+tag, for exampleab.+n.e.w.s@gmail.com. Only the username before+is varied now.Validation
a+b@gmail.comand long TLDs likex@example.photography.a..b@,.ab@,ab.@,a@b..comanda@-b.com.UX / a11y / HTML
#errorMsgelement (previously unused), which hasrole="alert". The input getsaria-invalidand is linked witharia-describedby. There is also arole="status"message.novalidateform.<h2>…</h3>mismatch. The page now has a singleh1, and the attribution line is a paragraph.Dependencies
cdn.sheetjs.com). cdnjs stops at 0.18.5, and versions before 0.20.2 are affected by CVE-2023-30533 and CVE-2024-22363. Both affect parsing, not the write-only use here, but this moves the app off known-vulnerable code.Docs
Verification
node --check main.jspasses.generateEmailVariationsandcountEmailVariations:abcgives 4,john.doegives 64,ab+newsgives 2, a 14-character username gives 8192/8192, a 15-character one gives 8192/16384, and a 64-character one finishes in about 5 ms..., and passes the new validator.generateAndDisplayVariations:aria-invalid.exportToExcel()against SheetJS 0.20.3 in Node. It producedemail_variations.xlsxwith sheetEmailVariations, and reading it back gave a header plus 64 rows.application/javascript, with CORS*. fadyehabamer.com and the Vercel demo return 200.main.jsexists inindex.html. CRLF line endings are preserved.