Repository navigation
Conversation
…e://, zoommtg://) (#1108) The sanitize schema allowed only web, mail and file: links, so links such as obsidian://open?vault=... lost their href and rendered as dead text in chat and in the file preview. A fixed list of note, editor and meeting app schemes now passes both the schema and the URL transform. It is an allowlist rather than "anything but javascript:" because the text comes from the model and from repository files, and OS handlers such as ms-msdt: and search-ms: have been exploited through clicked links. These links open in a new tab with noopener/noreferrer like other external chat links. The file preview now does the same for its web and app links, which used to replace Pi Web in the current tab; relative, in-page and local file links are unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Links such as
obsidian://open?vault=…lost theirhrefand rendered as dead text in chat and in the file preview: the sanitize schema allowed only web, mail andfile:links, and the URL transform strips the rest.lib/markdown.ts: a fixed list of app schemes passes both the sanitizer (links only; images from them stay blocked) and a newmarkdownAppUrlTransform, used where no local-file handler is present.file:links keep their existing handling.obsidian,logseq,notion; editors:vscode,vscode-insiders,cursor,zed,jetbrains; meetings/chat:zoommtg,zoomus,msteams,slackjavascript:": the text comes from the model and from repository files, and OS handlers such asms-msdt:andsearch-ms:have been exploited through clicked links. No setting or env var; more schemes can be added by PR.components/MarkdownBody.tsx: app links open withtarget="_blank" rel="noopener noreferrer"like other chat links.components/FileViewer.tsx: behaviour change — web and app links in the markdown preview now also open in a new tab; they used to replace Pi Web in the current tab. Relative, in-page (#…) and local-file links are unchanged.Tests:
lib/markdown.test.mjs(both pipelines, raw HTML links, blocked schemesjavascript:,vbscript:,data:,blob:,ms-msdt:,search-ms:,intent:, unknown ones, images),components/MarkdownBody.test.mjs,components/FileViewer.test.mjs.tsc, eslint,npm testpass.Closes #1108
🤖 Generated with Claude Code