Skip to content

fix(#184): escape HTML on first speculative update - #186

Merged
BearToCode merged 1 commit into
masterfrom
escape-overlay
Oct 7, 2026
Merged

BearToCode merged 1 commit into
masterfrom
escape-overlay

Conversation

@BearToCode

Copy link
Copy Markdown
Owner

Actually fix the issue mentioned by @itsmunzir and @imunisasi in #184

@itsmunzir

Copy link
Copy Markdown
Contributor

Checked the helper: the escape order is right — & is replaced first, so a literal < someone typed stays < and cannot turn back into a tag.

This branch shipped broken twice (4.11.3 returned the raw text; 4.11.4 only sanitized when a sanitizer was configured), so it deserves one guard before the next release. The package has no test runner today, so the smallest check is the reporter's own repro against this branch: open an empty editor, type <img src=x onerror=alert(1)>, and confirm the overlay paints that text literally while the first highlight pass is still pending. If vitest lands here later, the one-line case is speculativeHighlightUpdate('', '<img src=x onerror=alert(1)>', '') returning &lt;img src=x onerror=alert(1)&gt;.

Nothing else from me on this one.

@BearToCode
BearToCode merged commit c34cc7e into master Oct 7, 2026
2 checks passed
@BearToCode
BearToCode deleted the escape-overlay branch October 7, 2026 14:48
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

🎉 This PR is included in version carta-md-v4.11.5 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants