Skip to content

fix(sse): escape backslash in ChatGPT-web citation link text (#6569) - #6944

Merged
diegosouzapw merged 3 commits into
diegosouzapw:release/v3.8.47from
brick30llc-ctrl:fix/6569-citations-backslash-escape
Jul 12, 2026
Merged

diegosouzapw merged 3 commits into
diegosouzapw:release/v3.8.47from
brick30llc-ctrl:fix/6569-citations-backslash-escape

Conversation

@brick30llc-ctrl

Copy link
Copy Markdown
Contributor

What

markdownLinkText() (ChatGPT-web citation renderer) escaped [ and ] but not the backslash itself. A citation label ending in — or containing — a backslash therefore produced a broken Markdown link:

  • Label Path C:\ → [Path C:\](url) — the trailing \ escapes the closing ], consuming the link's bracket.
  • Label a\[b → [a\\[b](url) — the bare \ before [ corrupts the escaping.

Fix: escape the backslash first, then the brackets.

Why

This is the sole real issue among the CodeQL js/incomplete-sanitization alerts blocking the v3.8.47 release PR (#6569) — open-sse/executors/chatgpt-web/citations.ts:52 (2 of the 9 new alerts flagged on the large release diff). The remaining 7 CodeQL alerts on #6569 are false positives (SHA-256 used for a device-fingerprint UA header / cache key / display-label suffix — not credential hashing; .includes() in test-file assertions; and an errorResponse that already routes through sanitizeErrorMessage(), the known Rule #14 / ERROR_SANITIZATION.md precedent).

Test (TDD)

New tests/unit/chatgpt-web-citations-escape.test.ts — failing-then-passing:

  • trailing backslash in the label
  • backslash preceding a bracket (no bracket leak)
  • bracket-only labels (regression guard — existing escaping preserved)
  • plain labels pass through unchanged
node --import tsx/esm --test tests/unit/chatgpt-web-citations-escape.test.ts  → 4/4 pass
node --import tsx/esm --test tests/unit/chatgpt-web-citations.test.ts         → 3/3 pass (no regression)

ESLint clean on both changed files. (Pre-existing omniglyph typecheck errors are unrelated — identical on the base ref.)

markdownLinkText() escaped [ and ] but not the backslash itself, so a
citation label ending in (or containing) a backslash produced a broken
Markdown link — e.g. [Path C:\](url), where the trailing \ escapes the
closing bracket and consumes the link. Escape the backslash first, then
the brackets.

Clears the CodeQL js/incomplete-sanitization alerts at
open-sse/executors/chatgpt-web/citations.ts:52 (2 of the 9 new alerts
on the v3.8.47 release PR).

Regression guard: tests/unit/chatgpt-web-citations-escape.test.ts
(trailing backslash, backslash-before-bracket, bracket-only, plain).
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@diegosouzapw

Copy link
Copy Markdown
Owner

Thanks for the fix and the clean TDD test — verified locally: reverting only the markdownLinkText() change (keeping your new test) makes 2/4 assertions fail with exactly the broken output described in the PR body ([Path C:\](url) losing its closing bracket), and restoring the fix brings it back to 4/4 with no regression on the existing chatgpt-web-citations.test.ts suite (7/7 total). Escaping the backslash before the brackets is the right order — it guarantees any run of N backslashes becomes an even 2N, so it can never leak past the ] escape. Confirmed this is complementary to #6635 (d76aa40), not a duplicate — that commit never touched backslash escaping.

One thing missing before merge: this repo aggregates the changelog via per-PR fragments in changelog.d/ (see changelog.d/README.md) rather than editing CHANGELOG.md directly. Could you add changelog.d/fixes/6944-<slug>.md with a one-line bullet crediting yourself? Happy to help if useful — otherwise this looks merge-ready once that's added.

diegosouzapw and others added 2 commits July 12, 2026 10:24
Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
@diegosouzapw
diegosouzapw merged commit 7ca422d into diegosouzapw:release/v3.8.47 Jul 12, 2026
1 check passed
@diegosouzapw

Copy link
Copy Markdown
Owner

Merged — escapes backslash before brackets in ChatGPT-web citation link text (7/7 tests green, added a changelog fragment). Thanks @brick30llc-ctrl! (Remaining red checks are pre-existing release-tip base-reds tracked in #6967, unrelated to this fix.)

@diegosouzapw diegosouzapw mentioned this pull request Jul 13, 2026
@diegosouzapw diegosouzapw mentioned this pull request Jul 28, 2026
HouMinXi pushed a commit to HouMinXi/OmniRoute that referenced this pull request Aug 2, 2026
…uzapw#6569) (diegosouzapw#6944)

* fix(sse): escape backslash in ChatGPT-web citation link text (diegosouzapw#6569)

markdownLinkText() escaped [ and ] but not the backslash itself, so a
citation label ending in (or containing) a backslash produced a broken
Markdown link — e.g. [Path C:\](url), where the trailing \ escapes the
closing bracket and consumes the link. Escape the backslash first, then
the brackets.

Clears the CodeQL js/incomplete-sanitization alerts at
open-sse/executors/chatgpt-web/citations.ts:52 (2 of the 9 new alerts
on the v3.8.47 release PR).

Regression guard: tests/unit/chatgpt-web-citations-escape.test.ts
(trailing backslash, backslash-before-bracket, bracket-only, plain).

* chore(changelog): add changelog.d fragment for diegosouzapw#6944

Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>

---------

Co-authored-by: brick30llc-ctrl <admin@brick30.com>
Co-authored-by: Diego Rodrigues de Sa e Souza <diegosouza.pw@gmail.com>
Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…uzapw#6569) (diegosouzapw#6944)

* fix(sse): escape backslash in ChatGPT-web citation link text (diegosouzapw#6569)

markdownLinkText() escaped [ and ] but not the backslash itself, so a
citation label ending in (or containing) a backslash produced a broken
Markdown link — e.g. [Path C:\](url), where the trailing \ escapes the
closing bracket and consumes the link. Escape the backslash first, then
the brackets.

Clears the CodeQL js/incomplete-sanitization alerts at
open-sse/executors/chatgpt-web/citations.ts:52 (2 of the 9 new alerts
on the v3.8.47 release PR).

Regression guard: tests/unit/chatgpt-web-citations-escape.test.ts
(trailing backslash, backslash-before-bracket, bracket-only, plain).

* chore(changelog): add changelog.d fragment for diegosouzapw#6944

Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>

---------

Co-authored-by: brick30llc-ctrl <admin@brick30.com>
Co-authored-by: Diego Rodrigues de Sa e Souza <diegosouza.pw@gmail.com>
Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants