diff options
Diffstat (limited to 'shared')
| -rw-r--r-- | shared/Notify.qml | 9 |
1 files changed, 8 insertions, 1 deletions
diff --git a/shared/Notify.qml b/shared/Notify.qml index 1abe57d..cb1e2fe 100644 --- a/shared/Notify.qml +++ b/shared/Notify.qml @@ -75,6 +75,13 @@ Singleton { // not just the first, so a decoy attribute cannot shadow a remote one; // entities are decoded before the test, so an encoded scheme cannot slip // past. + // + // The body renders as Markdown, so the same rule covers its image syntax: + // `` and `![alt][ref]` fetch just as an <img> does, and parsing + // their destinations would mean reimplementing CommonMark's link grammar. + // Escaping the bracket turns every one into literal text instead, local or + // not. Raw HTML inside Markdown goes through Qt's HTML importer, so the + // tag filter below still applies to it. function sanitize(body) { function decode(s) { return s.replace(/&(?:#x([0-9a-f]+)|#(\d+)|(amp|colon|sol|tab|quot));/gi, @@ -84,7 +91,7 @@ Singleton { return { amp: "&", colon: ":", sol: "/", tab: "\t", quot: "\"" }[name.toLowerCase()]; }); } - return (body || "").replace(/<img\b[^>]*>/gi, function (tag) { + return (body || "").replace(/!\[/g, "!\\[").replace(/<img\b[^>]*>/gi, function (tag) { const re = /(?:^|\s)src\s*=\s*(?:"([^"]*)"|'([^']*)'|([^\s>]+))/gi; let m, found = false, local = true; while ((m = re.exec(tag))) { |
