| Age | Commit message (Collapse) | Author | Files | Lines |
|
Balloon and drawer bodies switch from RichText to Qt's MarkdownText
(CommonMark plus GitHub extensions). Raw HTML still goes through Qt's
HTML importer, so body-markup senders keep working.
Markdown images fetch their destination the same way an <img> does,
which the existing sanitize filter would miss since it only inspects
tags. sanitize now escapes every "![" so the syntax renders as literal
text, local or remote; parsing CommonMark destinations and reference
definitions to allow local ones is not worth the grammar. Verified in
the shell log: before the filter reached the running shell, a test
body fetched https://example.org/a.png; after, a second one did not.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
|
The sanitizer matched the first \bsrc anywhere in the tag, so a
data-src="file:///tmp/decoy" before a remote src won the match and kept
the whole tag while Qt, which ignores data-src, fetched the remote
image. Scan every src assignment in the tag and keep it only if all of
them are local. Also set cache: false on the balloon preview, since the
daemon overwrites the same path on a replace and QQuickPixmapCache keys
on URL, so a replaced notification could show the previous image.
|
|
The http(s)-only regex let protocol-relative //host, ftp, data and
entity-encoded schemes through, and the comment overstated what it
removed. Replace it with a deny-by-default allowlist: an <img> is
removed unless its src, entities decoded first, is a file: URL or a
single leading slash. Protocol-relative //host is rejected while a
/absolute/path is kept.
|
|
A notification is untrusted input. Inline <img> now renders only for
local sources; an http(s) source is removed before the RichText body is
shown, so a remote sender cannot make the shell fetch a URL. The row and
the balloon share the one sanitizer in the Notify singleton.
|
|
Mirror the balloon's right-click close-all on the drawer row: the spec says
the gestures are identical in both forms, and a right-click on a row
previously did nothing. The right-button branch precedes the live guard so it
behaves the same on history rows.
Stop importing the Status singleton into the notification shell. Referencing
it instantiated it, and its onPresentationChanged writes status.dnd and runs
breaktimer.sh, so a read-only consumer was writing state and shelling out on
every presentation toggle, and doubled the dndBeforePresentation race. Notify
now reads "/run/user/<uid>/status.dnd" directly through a FileView, the same
convention as the notifyd files; a missing file means off.
AGENTS.md named Drawer.qml as the drawer's reserved space; it is
desktop/NotificationList.qml.
|
|
The daemon publishes its queue, history, drawer flag and snooze as files;
this reads them for both renderers, the same files-are-the-interface
convention the status registry set. Mutations and the rofi action picker run
notifyctl through a Process, which is the one path back to the daemon.
|