mirror of
https://github.com/Kilo-Org/kilocode.git
synced 2026-09-24 16:02:55 +08:00
Merge pull request #7440 from Kilo-Org/mark/fix-codespan-html-escape
fix(ui): escape HTML in codespan renderer to prevent tag injection
This commit is contained in:
@@ -632,12 +632,18 @@ export const { use: useMarked, provider: MarkedProvider } = createSimpleContext(
|
||||
// kilocode_change start
|
||||
codespan({ text }) {
|
||||
const file = parseFilePath(text)
|
||||
const escaped = text
|
||||
.replace(/&/g, "&")
|
||||
.replace(/</g, "<")
|
||||
.replace(/>/g, ">")
|
||||
.replace(/"/g, """)
|
||||
.replace(/'/g, "'")
|
||||
if (file) {
|
||||
const lineAttr = file.line ? ` data-file-line="${file.line}"` : ""
|
||||
const colAttr = file.column ? ` data-file-col="${file.column}"` : ""
|
||||
return `<code class="file-link" data-file-path="${file.path}"${lineAttr}${colAttr}>${text}</code>`
|
||||
return `<code class="file-link" data-file-path="${file.path}"${lineAttr}${colAttr}>${escaped}</code>`
|
||||
}
|
||||
return `<code>${text}</code>`
|
||||
return `<code>${escaped}</code>`
|
||||
},
|
||||
code({ text, lang }) {
|
||||
const escaped = text
|
||||
|
||||
Reference in New Issue
Block a user