Repository navigation
Conversation
#44 (blockquote laziness) and #45 (table detection) were merged in that order. #44 used PATTERN_TABLE_SEPARATOR in quoteLineState(), #45 deleted the constant, so every blockquote now throws "Error: Undefined constant Lexer::PATTERN_TABLE_SEPARATOR" on main (40 test errors). The check added nothing to blockquote laziness; drop it. (cherry picked from commit 7e799b1, pushed to the #44 branch after #44 had already been merged) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CPcuaaxrCottkeL1ykoSWe
…links Two URL safety checks had drifted apart: InlineParser::isSafeLinkUrl() (trims spaces, allows inner spaces) and HtmlSanitizer::isSafeUrl() (decodes then rejects any space, no trimming). Both now call Sanitizer\UrlValidator::isSafe(), which keeps the stricter rule of each: controls rejected raw or percent-encoded, leading/trailing spaces trimmed before the scheme check, protocol-relative and backslash URLs rejected, and the scheme allowlist applied to both the URL and its percent-decoded form. The autolink script-scheme list moves there too. The renderer emitted target="_blank" without rel="noopener" when only linkTarget was configured (reverse tabnabbing on older browsers), while HtmlSanitizer already enforced it for raw HTML links. noopener is now added (or appended to linkRel) for _blank targets. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CPcuaaxrCottkeL1ykoSWe
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problème (points 13 et 14 de la review)
13. Deux validations d'URL qui divergeaient
InlineParser::isSafeLinkUrl()HtmlSanitizer::isSafeUrl()/my uri)%6Aavascript:Deux règles différentes pour la même question : c'est le genre d'écart qui a produit le bypass corrigé dans #46.
14. Avec seulement
linkTarget: '_blank', le renderer émettaittarget="_blank"sansrel="noopener"(risque de reverse tabnabbing), alors que le sanitizer l'impose déjà pour le HTML brut.Correctif
Sanitizer\UrlValidator::isSafe(), utilisé par l'InlineParser (liens, images, références) et par le HtmlSanitizer (hrefetsrc). Il garde la règle la plus stricte de chaque version ://…) et préfixées par\rejetées ;http,https,mailto, relatif) appliquée à l'URL et à sa forme percent-décodée.javascript,vbscript,data) y est déplacée :UrlValidator::hasScriptScheme().target="_blank"ajoute toujoursnoopener, ou le complète silinkRelest fourni, sans doublon et sans tenir compte de la casse. Les autres valeurs detargetet les autoliens e-mail ne changent pas.Changements de comportement mineurs
<a href="a%20b">), comme les liens Markdown./qui contient%3A(par exemplefoo%3Abar) est rejeté, puisque sa forme décodée ressemble à un schéma.Tests
tests/Unit/Sanitizer/UrlValidatorTest.php: 9 URL sûres, 14 vecteurs à rejeter, détection des schémas exécutables.tests/Unit/Renderer/LinkTargetRelTest.php: 4 tests surnoopener. Il n'existait aucun test surlinkTarget/linkRel.🤖 Generated with Claude Code
https://claude.ai/code/session_01CPcuaaxrCottkeL1ykoSWe
Generated by Claude Code