Bug
The guess form accepts any 5-letter combination of A-Z, including nonsense strings like ZZZZZ, QXWJK, etc. There is no check against the actual word list (src/data.js WORDS), so guesses that are not real dictionary words are silently accepted and scored.
Root cause
In src/components/GuessForm/GuessForm.js:
const validateLength = /([A-Z]){5}/g
if (!guess.match(validateLength)) {
return window.alert("Guess must have exactly 5 A-Z characters")
}
This regex (without ^/$ anchors, and named oddly as "validateLength") only verifies the input contains 5 uppercase letters. It does not check that the guess exists in the WORDS dictionary in src/data.js. As a result, any 5-letter uppercase string passes validation and is passed to addToGuessList/checkGuess, which will happily score it letter-by-letter against the answer.
Repro
const validateLength = /([A-Z]){5}/g;
"ZZZZZ".match(validateLength); // => ["ZZZZZ"] (truthy -> validation passes)
Confirmed via node repl in this repo: guess.match(validateLength) is truthy for ZZZZZ, so the alert is never shown and the invalid guess is submitted and scored like any real word.
Expected behavior
Guesses should be validated against the dictionary (WORDS array in src/data.js, or a larger valid-words list) and rejected with a message like "Not in word list" if they aren't real words, similar to actual Wordle.
Suggested fix
- Import
WORDS (or a dedicated allowed-guesses list) into GuessForm.js.
- After the length/character check, additionally verify
WORDS.includes(guess) before calling addToGuessList.
- Anchor the format regex (
/^[A-Z]{5}$/) as well, since the current one isn't anchored.
Bug
The guess form accepts any 5-letter combination of A-Z, including nonsense strings like
ZZZZZ,QXWJK, etc. There is no check against the actual word list (src/data.jsWORDS), so guesses that are not real dictionary words are silently accepted and scored.Root cause
In
src/components/GuessForm/GuessForm.js:This regex (without
^/$anchors, and named oddly as "validateLength") only verifies the input contains 5 uppercase letters. It does not check that the guess exists in theWORDSdictionary insrc/data.js. As a result, any 5-letter uppercase string passes validation and is passed toaddToGuessList/checkGuess, which will happily score it letter-by-letter against the answer.Repro
Confirmed via node repl in this repo:
guess.match(validateLength)is truthy forZZZZZ, so the alert is never shown and the invalid guess is submitted and scored like any real word.Expected behavior
Guesses should be validated against the dictionary (
WORDSarray insrc/data.js, or a larger valid-words list) and rejected with a message like "Not in word list" if they aren't real words, similar to actual Wordle.Suggested fix
WORDS(or a dedicated allowed-guesses list) intoGuessForm.js.WORDS.includes(guess)before callingaddToGuessList./^[A-Z]{5}$/) as well, since the current one isn't anchored.