PhoneNumberUtilityService.extractCountryCode greedy regex breaks NANP / isUSNumber #1014

Closed
opened 2026-08-12 07:27:30 +00:00 by spikerj · 1 comment
Owner

Summary

extractCountryCode uses /^\+(\d{1,3})/, so +1555… yields "155" instead of "1". That makes isUSNumber and getPhoneNumberType("mobile") wrong for real NANP numbers.

Found by

Wave 6 coverage tick 7 a3 — adversarial tests on SMS phone utilities (ce1736f4).

Expected

Country code parsing should prefer longest-match against a known calling-code list (or NANP-aware rules), not a greedy 1–3 digit capture.

Impact

US/Canada mobile validation and formatting paths can misclassify numbers.

## Summary `extractCountryCode` uses `/^\+(\d{1,3})/`, so `+1555…` yields `"155"` instead of `"1"`. That makes `isUSNumber` and `getPhoneNumberType("mobile")` wrong for real NANP numbers. ## Found by Wave 6 coverage tick 7 a3 — adversarial tests on SMS phone utilities (`ce1736f4`). ## Expected Country code parsing should prefer longest-match against a known calling-code list (or NANP-aware rules), not a greedy 1–3 digit capture. ## Impact US/Canada mobile validation and formatting paths can misclassify numbers.
Author
Owner

Already present on spikersoft-angular master (d9bae78a). extractCountryCode treats +1 as NANP country code 1 before the greedy 1–3 digit capture, so isUSNumber / mobile typing work for real NANP numbers. Closing.

Already present on `spikersoft-angular` `master` (`d9bae78a`). `extractCountryCode` treats `+1` as NANP country code `1` before the greedy 1–3 digit capture, so `isUSNumber` / mobile typing work for real NANP numbers. Closing.
Sign in to join this conversation.