Skip to content

fix(preview): fence version cells so a backtick cannot break the PR comment table - #1260

Merged
BryanFRD merged 1 commit into
mainfrom
fix/preview-backtick-span
Oct 3, 2026
Merged

BryanFRD merged 1 commit into
mainfrom
fix/preview-backtick-span

Conversation

@BryanFRD

@BryanFRD BryanFRD commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Closes #1234

The version columns of the preview comment were wrapped in a single-backtick code span and passed through escape_md_cell, which escapes with backslashes. Markdown ignores backslash escapes inside a code span, so a backtick in a version still closed the span, and \ or < showed up literally.

Version cells now go through code_cell: the fence is one backtick longer than the longest run in the value, padded with a space when the value starts or ends with a backtick, as CommonMark specifies. Inside the span only | is escaped (GFM splits table cells before inline parsing) and newlines become spaces. Everything else stays literal, which is safe because a code span renders nothing as HTML. Name and bump cells keep escape_md_cell.

The existing hostile-input test asserted the broken output; it now expects the fenced form.

@BryanFRD
BryanFRD enabled auto-merge (squash) October 3, 2026 10:28

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nothing blocking. code_cell follows CommonMark code span rules. The fence is one backtick longer than the longest run inside, so the span can't close early. The padding is only added when the value starts or ends with a backtick, and the renderer strips exactly that one space. Leaving HTML entities unescaped is correct here, because inside a code span they would show up literally. \| is the GFM-sanctioned way to keep a pipe inside a code span in a table cell. The tests cover the cases that matter, including the empty value.

@BryanFRD
BryanFRD merged commit af150b0 into main Oct 3, 2026
32 checks passed
@BryanFRD
BryanFRD deleted the fix/preview-backtick-span branch October 3, 2026 10:31
ferrflow Bot added a commit that referenced this pull request Oct 3, 2026
## [7.27.2] - 2026-10-03

### Bug Fixes

- fix(forge): encode branch names in PR lookups and stop set_branch from hiding a PATCH error (#1261)
- fix(preview): fence version cells so a backtick cannot break the PR comment table (#1260)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(preview): a backtick in a version still breaks the PR comment table

1 participant