# Mode 3, HTML attr-quote typo sweep

Bug class: an attribute value opens with `"`, embeds unescaped `"` characters,
and closes with another `"`, the parser closes the value at the second quote
and sprays the rest as junk attributes:

```html
<div data-artifact-label="name="attachment"">
<!-- parses as data-artifact-label="" + attachment + "" -->
```

Sibling traps in the same family: `\"` inside attribute values (JSON pasted
into HTML, backslash escapes don't exist in HTML) and `data-x="&quot;…` (an
entity-opened quote never closed), both swallow the parser past the next
quote. Sweep them with the same one-attribute-at-a-time discipline.

Scope: rendered HTML files only. Not for `<script>` blocks, JS template
literals, Markdown, JSX, or single isolated typos (targeted edit instead).

## Audit (narrow regex, never a broad one)

```js
// An attribute closes with " and the next char is not whitespace or >
const RE = new RegExp(`${ATTR}="[^"]*"(?=[^\\s>])`, 'g');
```

One-shot: walk `**/*.html` under the target root, count matches per file,
report counts to the user before fixing. Zero matches → stop.

Attribute order (run each independently, never one glob regex over all):
`data-artifact-label` → `data-note` → `aria-label` → `title` → `alt` →
`placeholder`.

## Fix (greedy capture, stops at `>`, never crosses a tag boundary)

```js
const FIX = new RegExp(
  `${ATTR}="([^>]*[a-z0-9][a-z0-9_-]*="[^"]*")"(?=[\\s>])`, 'g');
const fixed = html.replace(FIX, (_m, value) =>
  value.includes("'")
    ? `${ATTR}="${value.replace(/"/g, '&quot;')}"`   // value has ', entity-escape
    : `${ATTR}='${value}'`);                          // else single-quote outside
```

Remaining hits after the automated pass are edge cases (trailing prose, no
`ident=` prefix), fix each with a targeted edit; do not extend the regex.

## Anti-patterns

- Never sweep with a broad regex like `="[^"]*"[^"]*"` across all attributes, thousands of false positives on legitimate multi-attribute tags.
- Never use the non-greedy capture variant, it stops at the first `"` and
  captures only `name=` instead of `name="attachment"`.
- Never run the regexes inside `<script>` blocks, JS quoting rules differ.
- Never skip the re-audit after the automated pass.
- Never commit the one-shot script, run from the scratchpad or `node -e`.

## Verification (all three)

1. Re-audit → 0 remaining broken values.
2. Tag balance per touched file: `(<div\b)` count === `(</div>)` count (same
   for section, grid-ui, article, …).
3. If a dev server is up, curl a sample of fixed pages → HTTP 200.
