aboutsummaryrefslogtreecommitdiffstats
path: root/shared/Notify.qml
diff options
context:
space:
mode:
Diffstat (limited to 'shared/Notify.qml')
-rw-r--r--shared/Notify.qml9
1 files changed, 8 insertions, 1 deletions
diff --git a/shared/Notify.qml b/shared/Notify.qml
index 1abe57d..cb1e2fe 100644
--- a/shared/Notify.qml
+++ b/shared/Notify.qml
@@ -75,6 +75,13 @@ Singleton {
// not just the first, so a decoy attribute cannot shadow a remote one;
// entities are decoded before the test, so an encoded scheme cannot slip
// past.
+ //
+ // The body renders as Markdown, so the same rule covers its image syntax:
+ // `![alt](url)` and `![alt][ref]` fetch just as an <img> does, and parsing
+ // their destinations would mean reimplementing CommonMark's link grammar.
+ // Escaping the bracket turns every one into literal text instead, local or
+ // not. Raw HTML inside Markdown goes through Qt's HTML importer, so the
+ // tag filter below still applies to it.
function sanitize(body) {
function decode(s) {
return s.replace(/&(?:#x([0-9a-f]+)|#(\d+)|(amp|colon|sol|tab|quot));/gi,
@@ -84,7 +91,7 @@ Singleton {
return { amp: "&", colon: ":", sol: "/", tab: "\t", quot: "\"" }[name.toLowerCase()];
});
}
- return (body || "").replace(/<img\b[^>]*>/gi, function (tag) {
+ return (body || "").replace(/!\[/g, "!\\[").replace(/<img\b[^>]*>/gi, function (tag) {
const re = /(?:^|\s)src\s*=\s*(?:"([^"]*)"|'([^']*)'|([^\s>]+))/gi;
let m, found = false, local = true;
while ((m = re.exec(tag))) {