Repository navigation
fix(#184): escape the overlay's plain-text fallback - #185
Merged
Merged
Conversation
`speculativeHighlightUpdate` returns the editor's text unchanged when the overlayhas no `.line` spans (before the highlighter's first pass, or when asanitizer strips those spans). The caller parses that return value as HTML andnever runs the configured sanitizer over it, so markup typed into the editorexecuted inside the overlay. The fallback now escapes `&`, `<` and `>`, with a regression test that runsthe reported repro: the old code fails it, the new code passes.
Owner
|
Thanks for your contribution. However, I think it's a better idea to just update the following function by calling the sanitizer specified as a carta/packages/carta-md/src/lib/internal/components/Input.svelte Lines 131 to 161 in 3310d24 |
Removed allowBuilds section from pnpm workspace configuration.
Add early return if no lines are found in the tree.
Contributor
Author
|
Thanks - I see you implemented it on the branch. The speculative path now runs the configured |
|
🎉 This PR is included in version carta-md-v4.11.4 🎉 The release is available on: Your semantic-release bot 📦🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #184
speculativeHighlightUpdatereturns the editor's text unchanged when the overlay has no.linespans. Two ordinary paths reach it: the overlay is empty until the highlighter's first pass, and asanitizerthat strips Shiki's<span class="line">wrappers leaves it that way permanently. The caller renders the return value with{@html displayedOverlay.html}and never runs the configured sanitizer over this path, so markup typed into the editor was parsed and executed inside the overlay (the report's<img onerror>repro).The fallback now escapes
&,<and>. With no highlighted lines to patch, the overlay shows plain text either way, so the escape changes how the text is parsed, not what it says.Test
The repo has no test runner, so this ships a dependency-free
node:testcheck that runs the reported repro against the built package:The old code fails it (the returned string still contains
<img); the new code passes. Happy to move it under a runner if you add one later.