Repository navigation
Reject invalid raw HTML tags, attributes and email autolinks - #154
Merged
Merged
Conversation
- Tag names must start with an ASCII letter: <33>, < a> and </1a> are not raw HTML (spec examples 618 and 621). - Attribute names must start with an ASCII letter, _ or :, not a digit. - Unquoted attribute values must be non-empty: <a b=>c> and <a b=`c> are not raw HTML. - The atext set of email autolinks had \ where ' belongs: <foo\+@bar.example.com> is not an autolink (spec example 606).
This was referenced Oct 1, 2026
Fix inline raw HTML spanning lines: restore tokens, CommonMark 0.31 comments, linear-time guard
#156
Merged
Contributor
Author
|
Automated review: Codex CLI ( Verdict: signed off, no changes requested.
Codex could not run |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Split out of #152.
Bugs: invalid raw HTML and email autolinks were accepted.
<33>,< a>,</1a><b 1=c>_or:<a b=>c>,<a b=`c>"'=<>`<foo\+@bar.example.com>\where'belongsFix:
tag_namechecks the first character,attribute_nameno longer accepts a digit first,attribute_valuerejects an empty unquoted value, andchar_is_atext_plus_dothas'instead of\.Spec examples fixed: 606, 618. Example 621 also needs #156 (the last line of the example is dropped without it).
Tests:
src/cmark_html/invalid_raw_html_test.mbt. Updatedraw_html_test.mbt(</1div>,<.div>) andraw_html_wbtest.mbt(tag_nameon1div), which encoded the old behaviour.Depends on: nothing, independent of the other PRs.