Website feedback: double backslashes so escapes can't rebuild references; queue every approval

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
saphidandClaude Opus 5.5 committed 2026-09-28 14:51:18 +10:00
1 parent a6fff434a4
commit a7663b3a5e
3 files changed
+5 -1

No files matched your search

@@ -18,6 +18,7 @@ jobs:
concurrency:
group: approve-contributor
cancel-in-progress: false
queue: max
runs-on: ubuntu-latest
permissions:
contents: write
+3 -1
View File
@@ -21,10 +21,12 @@ const oneLine = (value, max) => String(value ?? "").replace(/\s+/g, " ").trim().
// (#1, owner/repo#1, GH-1, github.com links) would add backlinks to other
// people's issues, so break them all with a zero-width space. Escaping & first
// stops &commat; and &num; from turning back into @ and # when GitHub renders,
// and escaping < keeps out raw HTML such as an unclosed <!-- comment.
// escaping < keeps out raw HTML such as an unclosed <!-- comment, and doubling
// backslashes stops GH\-1 or github\.com from being unescaped back into references.
const ZWSP = "\u200b";
export function defang(text) {
return text
.replace(/\\/g, "\\\\")
.replace(/&/g, "&amp;")
.replace(/</g, "&lt;")
.replace(/@(?=[A-Za-z0-9])/g, `@${ZWSP}`)
+1
View File
@@ -59,6 +59,7 @@ test("breaks mentions, issue refs and table cells in user text", () => {
assert.equal(defang("see valve/steam#7 and GH-8"), "see valve/steam#\u200b7 and GH\u200b-8");
assert.equal(defang("&commat;valve &#64;valve &num;3"), "&amp;commat;valve &amp;#\u200b64;valve &amp;num;3");
assert.equal(defang("end <!--"), "end &lt;!--");
assert.equal(defang("GH\\-1 github\\.com"), "GH\\\\-1 github\\\\.com");
assert.equal(defang("https://github.com/a/b/issues/1"), "https://github\u200b.com/a/b/issues/1");
const issue = buildIssue(validate(form({ os: "a | b" })).value);
assert.match(issue.body, /\| a \\\| b \|/);