microsoft / microsoft/playwright-python

[Bug]: RegExp values are not serialized by evaluate(), and returned RegExps leak internal protocol JSON

Open
#3,188 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
15k
Forks
1.2k
Avg merge
55m
Merged PRs (30d)
4

Description

Version

1.62.0

Steps to reproduce
import re
from playwright.sync_api import sync_playwright

with sync_playwright() as p:
    browser = p.chromium.launch()
    page = browser.new_page()

    # 1. Passing a compiled pattern in
    print(page.evaluate("(v) => [typeof v, String(v)]", re.compile(r"a\d+", re.I)))

    # 2. Getting a RegExp back out
    print(page.evaluate("() => /a\\d+/gi"))

    # 3. Nested in a structure
    print(page.evaluate("() => ({x: [/foo/m]})"))

    browser.close()
Expected behavior
  1. ['object', '/a\\d+/i'], and the value is a real RegExp inside the page.
  2. re.compile('a\\d+', re.IGNORECASE)
  3. {'x': [re.compile('foo', re.MULTILINE)]}

This is what playwright-dotnet does today. EvaluateArgumentValueConverter.cs serializes Regex (line 138) and parses "r" back into a Regex (line 351).

Actual behavior
  1. ['undefined', 'undefined'], the argument is silently dropped
  2. {'r': {'p': 'a\\d+', 'f': 'gi'}}
  3. {'x': [{'r': {'p': 'foo', 'f': 'm'}}]}

Two separate problems, both silent:

  • serialize_value() in playwright/_impl/_js_handle.py has no branch for re.Pattern, so a compiled pattern falls through to {"v": "undefined"}.
  • parse_value() has no branch for "r", so it hits the bare return value at the end and hands back the raw wire format. There is no way to tell from the outside that this dict is not the actual result.

The protocol supports this in both directions and the driver already implements both sides ({r: {p, f}} on serialize, new RegExp(v.r.p, v.r.f) on parse), so this is only missing on the Python side.

Additional context

Happy to send a PR, I have one ready. The serialize direction can reuse the existing escape_regex_flags() in _str_utils.py, which already maps re.IGNORECASE|DOTALL|MULTILINE to i/s/m for locators and route matching. The parse direction needs the inverse.

Two things worth an opinion before I do:

  1. JavaScript flags with no re equivalent (g, y, d, u, v). I would drop them rather than raise, since /foo/g is very common and raising would be worse than today's behavior. Note that playwright-dotnet's FromInlineFlags throws on these, which looks like a separate bug over there.
  2. A JS pattern that is not valid Python re syntax, for example /(?<name>x)/ (Python spells it (?P<name>x)). With this change that would raise from re.compile instead of returning the dict. I think raising is acceptable since the dict was never usable anyway, but let me know if you would rather it degrade some other way.
Environment
- Operating System: macOS 26.3.1
- CPU: arm64
- Browser: Chromium
- Python Version: 3.14.0

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in playwright/_impl/_js_handle.py, inspecting serialize_value() and parse_value(), then review escape_regex_flags() in _str_utils.py for existing flag handling. Reproduce the three evaluate() cases from the issue and add coverage for compiled patterns, returned RegExps, and nested values. Done means Python regex values serialize correctly and returned JavaScript RegExps become re.Pattern objects rather than protocol dictionaries.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
api
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Clearly specified
Newbie friendliness
72/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.