mirror of
https://github.com/saphid/frame-control.git
synced 2026-10-06 06:00:33 +02:00
Website feedback: double backslashes so escapes can't rebuild references; queue every approval
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
a6fff434a4
commit
a7663b3a5e
3 files changed
+5
-1
No files matched your search
@@ -18,6 +18,7 @@ jobs:
|
|||||||
concurrency:
|
concurrency:
|
||||||
group: approve-contributor
|
group: approve-contributor
|
||||||
cancel-in-progress: false
|
cancel-in-progress: false
|
||||||
|
queue: max
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
permissions:
|
permissions:
|
||||||
contents: write
|
contents: write
|
||||||
|
|||||||
@@ -21,10 +21,12 @@ const oneLine = (value, max) => String(value ?? "").replace(/\s+/g, " ").trim().
|
|||||||
// (#1, owner/repo#1, GH-1, github.com links) would add backlinks to other
|
// (#1, owner/repo#1, GH-1, github.com links) would add backlinks to other
|
||||||
// people's issues, so break them all with a zero-width space. Escaping & first
|
// people's issues, so break them all with a zero-width space. Escaping & first
|
||||||
// stops @ and # from turning back into @ and # when GitHub renders,
|
// stops @ and # from turning back into @ and # when GitHub renders,
|
||||||
// and escaping < keeps out raw HTML such as an unclosed <!-- comment.
|
// escaping < keeps out raw HTML such as an unclosed <!-- comment, and doubling
|
||||||
|
// backslashes stops GH\-1 or github\.com from being unescaped back into references.
|
||||||
const ZWSP = "\u200b";
|
const ZWSP = "\u200b";
|
||||||
export function defang(text) {
|
export function defang(text) {
|
||||||
return text
|
return text
|
||||||
|
.replace(/\\/g, "\\\\")
|
||||||
.replace(/&/g, "&")
|
.replace(/&/g, "&")
|
||||||
.replace(/</g, "<")
|
.replace(/</g, "<")
|
||||||
.replace(/@(?=[A-Za-z0-9])/g, `@${ZWSP}`)
|
.replace(/@(?=[A-Za-z0-9])/g, `@${ZWSP}`)
|
||||||
|
|||||||
@@ -59,6 +59,7 @@ test("breaks mentions, issue refs and table cells in user text", () => {
|
|||||||
assert.equal(defang("see valve/steam#7 and GH-8"), "see valve/steam#\u200b7 and GH\u200b-8");
|
assert.equal(defang("see valve/steam#7 and GH-8"), "see valve/steam#\u200b7 and GH\u200b-8");
|
||||||
assert.equal(defang("@valve @valve #3"), "&commat;valve &#\u200b64;valve &num;3");
|
assert.equal(defang("@valve @valve #3"), "&commat;valve &#\u200b64;valve &num;3");
|
||||||
assert.equal(defang("end <!--"), "end <!--");
|
assert.equal(defang("end <!--"), "end <!--");
|
||||||
|
assert.equal(defang("GH\\-1 github\\.com"), "GH\\\\-1 github\\\\.com");
|
||||||
assert.equal(defang("https://github.com/a/b/issues/1"), "https://github\u200b.com/a/b/issues/1");
|
assert.equal(defang("https://github.com/a/b/issues/1"), "https://github\u200b.com/a/b/issues/1");
|
||||||
const issue = buildIssue(validate(form({ os: "a | b" })).value);
|
const issue = buildIssue(validate(form({ os: "a | b" })).value);
|
||||||
assert.match(issue.body, /\| a \\\| b \|/);
|
assert.match(issue.body, /\| a \\\| b \|/);
|
||||||
|
|||||||
Reference in new issue
Block a user