Repository navigation
fix(sse): escape backslash in ChatGPT-web citation link text (#6569) - #6944
Conversation
markdownLinkText() escaped [ and ] but not the backslash itself, so a citation label ending in (or containing) a backslash produced a broken Markdown link — e.g. [Path C:\](url), where the trailing \ escapes the closing bracket and consumes the link. Escape the backslash first, then the brackets. Clears the CodeQL js/incomplete-sanitization alerts at open-sse/executors/chatgpt-web/citations.ts:52 (2 of the 9 new alerts on the v3.8.47 release PR). Regression guard: tests/unit/chatgpt-web-citations-escape.test.ts (trailing backslash, backslash-before-bracket, bracket-only, plain).
|
Warning You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again! |
|
Thanks for the fix and the clean TDD test — verified locally: reverting only the One thing missing before merge: this repo aggregates the changelog via per-PR fragments in |
Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
|
Merged — escapes backslash before brackets in ChatGPT-web citation link text (7/7 tests green, added a changelog fragment). Thanks @brick30llc-ctrl! (Remaining red checks are pre-existing release-tip base-reds tracked in #6967, unrelated to this fix.) |
…uzapw#6569) (diegosouzapw#6944) * fix(sse): escape backslash in ChatGPT-web citation link text (diegosouzapw#6569) markdownLinkText() escaped [ and ] but not the backslash itself, so a citation label ending in (or containing) a backslash produced a broken Markdown link — e.g. [Path C:\](url), where the trailing \ escapes the closing bracket and consumes the link. Escape the backslash first, then the brackets. Clears the CodeQL js/incomplete-sanitization alerts at open-sse/executors/chatgpt-web/citations.ts:52 (2 of the 9 new alerts on the v3.8.47 release PR). Regression guard: tests/unit/chatgpt-web-citations-escape.test.ts (trailing backslash, backslash-before-bracket, bracket-only, plain). * chore(changelog): add changelog.d fragment for diegosouzapw#6944 Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com> --------- Co-authored-by: brick30llc-ctrl <admin@brick30.com> Co-authored-by: Diego Rodrigues de Sa e Souza <diegosouza.pw@gmail.com> Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
…uzapw#6569) (diegosouzapw#6944) * fix(sse): escape backslash in ChatGPT-web citation link text (diegosouzapw#6569) markdownLinkText() escaped [ and ] but not the backslash itself, so a citation label ending in (or containing) a backslash produced a broken Markdown link — e.g. [Path C:\](url), where the trailing \ escapes the closing bracket and consumes the link. Escape the backslash first, then the brackets. Clears the CodeQL js/incomplete-sanitization alerts at open-sse/executors/chatgpt-web/citations.ts:52 (2 of the 9 new alerts on the v3.8.47 release PR). Regression guard: tests/unit/chatgpt-web-citations-escape.test.ts (trailing backslash, backslash-before-bracket, bracket-only, plain). * chore(changelog): add changelog.d fragment for diegosouzapw#6944 Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com> --------- Co-authored-by: brick30llc-ctrl <admin@brick30.com> Co-authored-by: Diego Rodrigues de Sa e Souza <diegosouza.pw@gmail.com> Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
What
markdownLinkText()(ChatGPT-web citation renderer) escaped[and]but not the backslash itself. A citation label ending in — or containing — a backslash therefore produced a broken Markdown link:Path C:\→[Path C:\](url)— the trailing\escapes the closing], consuming the link's bracket.a\[b→[a\\[b](url)— the bare\before[corrupts the escaping.Fix: escape the backslash first, then the brackets.
Why
This is the sole real issue among the CodeQL
js/incomplete-sanitizationalerts blocking the v3.8.47 release PR (#6569) —open-sse/executors/chatgpt-web/citations.ts:52(2 of the 9 new alerts flagged on the large release diff). The remaining 7 CodeQL alerts on #6569 are false positives (SHA-256 used for a device-fingerprint UA header / cache key / display-label suffix — not credential hashing;.includes()in test-file assertions; and anerrorResponsethat already routes throughsanitizeErrorMessage(), the known Rule #14 /ERROR_SANITIZATION.mdprecedent).Test (TDD)
New
tests/unit/chatgpt-web-citations-escape.test.ts— failing-then-passing:ESLint clean on both changed files. (Pre-existing
omniglyphtypecheck errors are unrelated — identical on the base ref.)