Skip to content

Guesses like "ZZZZZ" (non-dictionary words) are accepted #7

Description

@copilot-swe-agent

Bug

The guess form accepts any 5-letter combination of A-Z, including nonsense strings like ZZZZZ, QXWJK, etc. There is no check against the actual word list (src/data.js WORDS), so guesses that are not real dictionary words are silently accepted and scored.

Root cause

In src/components/GuessForm/GuessForm.js:

const validateLength = /([A-Z]){5}/g

if (!guess.match(validateLength)) {
  return window.alert("Guess must have exactly 5 A-Z characters")
}

This regex (without ^/$ anchors, and named oddly as "validateLength") only verifies the input contains 5 uppercase letters. It does not check that the guess exists in the WORDS dictionary in src/data.js. As a result, any 5-letter uppercase string passes validation and is passed to addToGuessList/checkGuess, which will happily score it letter-by-letter against the answer.

Repro

const validateLength = /([A-Z]){5}/g;
"ZZZZZ".match(validateLength); // => ["ZZZZZ"]  (truthy -> validation passes)

Confirmed via node repl in this repo: guess.match(validateLength) is truthy for ZZZZZ, so the alert is never shown and the invalid guess is submitted and scored like any real word.

Expected behavior

Guesses should be validated against the dictionary (WORDS array in src/data.js, or a larger valid-words list) and rejected with a message like "Not in word list" if they aren't real words, similar to actual Wordle.

Suggested fix

  • Import WORDS (or a dedicated allowed-guesses list) into GuessForm.js.
  • After the length/character check, additionally verify WORDS.includes(guess) before calling addToGuessList.
  • Anchor the format regex (/^[A-Z]{5}$/) as well, since the current one isn't anchored.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions