diff options
| -rw-r--r-- | desktop/NotificationRow.qml | 2 | ||||
| -rw-r--r-- | notifications/NotificationBalloon.qml | 2 | ||||
| -rw-r--r-- | shared/Notify.qml | 9 |
3 files changed, 10 insertions, 3 deletions
diff --git a/desktop/NotificationRow.qml b/desktop/NotificationRow.qml index 923cc9e..35c468b 100644 --- a/desktop/NotificationRow.qml +++ b/desktop/NotificationRow.qml @@ -93,7 +93,7 @@ Rectangle { width: parent.width visible: text !== "" text: Notify.sanitize(row.notification.body) - textFormat: Text.RichText + textFormat: Text.MarkdownText wrapMode: Text.WordWrap maximumLineCount: 2 elide: Text.ElideRight diff --git a/notifications/NotificationBalloon.qml b/notifications/NotificationBalloon.qml index 49ec0b4..b01a848 100644 --- a/notifications/NotificationBalloon.qml +++ b/notifications/NotificationBalloon.qml @@ -124,7 +124,7 @@ Rectangle { width: parent.width visible: text !== "" text: Notify.sanitize(b.notification.body) - textFormat: Text.RichText + textFormat: Text.MarkdownText wrapMode: Text.WordWrap maximumLineCount: 3 elide: Text.ElideRight diff --git a/shared/Notify.qml b/shared/Notify.qml index 1abe57d..cb1e2fe 100644 --- a/shared/Notify.qml +++ b/shared/Notify.qml @@ -75,6 +75,13 @@ Singleton { // not just the first, so a decoy attribute cannot shadow a remote one; // entities are decoded before the test, so an encoded scheme cannot slip // past. + // + // The body renders as Markdown, so the same rule covers its image syntax: + // `` and `![alt][ref]` fetch just as an <img> does, and parsing + // their destinations would mean reimplementing CommonMark's link grammar. + // Escaping the bracket turns every one into literal text instead, local or + // not. Raw HTML inside Markdown goes through Qt's HTML importer, so the + // tag filter below still applies to it. function sanitize(body) { function decode(s) { return s.replace(/&(?:#x([0-9a-f]+)|#(\d+)|(amp|colon|sol|tab|quot));/gi, @@ -84,7 +91,7 @@ Singleton { return { amp: "&", colon: ":", sol: "/", tab: "\t", quot: "\"" }[name.toLowerCase()]; }); } - return (body || "").replace(/<img\b[^>]*>/gi, function (tag) { + return (body || "").replace(/!\[/g, "!\\[").replace(/<img\b[^>]*>/gi, function (tag) { const re = /(?:^|\s)src\s*=\s*(?:"([^"]*)"|'([^']*)'|([^\s>]+))/gi; let m, found = false, local = true; while ((m = re.exec(tag))) { |
