discourse/plugins/chat/spec/models
Régis HANOL 13280c1023
FIX: Escape markdown characters in upload filenames (#39133)
Filenames containing markdown formatting characters (`_`, `*`, `~`, `` `
``, `[`, `]`, `|`) would break upload markup when cooked. For example,
uploading `_test_file_.txt` generated:

    [_test_file_.txt|attachment](upload://...)

The underscores triggered emphasis parsing inside the link text, which
both rendered the filename incorrectly (with italics) and prevented the
`|attachment` marker from being recognized — losing the
`class="attachment"` on the resulting `<a>` tag.

**Markdown generation (defense in depth)**

Add `escapeMarkdownCharacters` (JS) and `UploadMarkdown.escape_markdown`
(Ruby) to backslash-escape all inline formatting characters in filenames
before embedding them in markdown link text. Applied in:

- `UploadMarkdown` — image, attachment, and playable media methods
- `uploads.js` — `attachmentMarkdown` and `markdownNameFromFileName`
- `inline_uploads.rb` — HTML anchor conversion and hotlinked image URLs
- `to-markdown.js` — HTML-to-markdown attachment link reconstruction
- `sanitizeAlt` in `markdown-image-builder.js` — image alt text

**Parser resilience (belt and suspenders)**

The markdown-it `renderAttachment` renderer and ProseMirror's link
parser both assumed `tokens[idx+1]` was a single text token containing
the full link text. When emphasis/bold/strikethrough/code was parsed
inside the link text, the token sequence included formatting tokens and
the `|attachment` marker was lost. Both now scan forward through all
tokens between `link_open` and `link_close` to find the marker.

The image renderer (`renderImageOrPlayableMedia`) split alt text on `|`
assuming the first segment was always the alt and everything after was
structured suffixes (dimensions, video/audio, data attributes). A pipe
in the filename would produce extra segments that confused the dimension
parser. It now scans from the right, consuming known suffixes, and
treats everything remaining as alt text.

https://meta.discourse.org/t/400079
2026-04-14 10:37:41 +02:00
..
chat FIX: Escape markdown characters in upload filenames (#39133) 2026-04-14 10:37:41 +02:00
category_spec.rb DEV: add shortcut fab!(:variable, :fabricator) to specs (#33577) 2025-07-11 11:16:34 -03:00
user_option_spec.rb FEATURE: One-click chat reaction settings (#32150) 2025-04-04 09:15:13 +02:00
user_spec.rb DEV: Remove unnecessary rails_helper requiring (#26364) 2024-03-26 11:32:01 +01:00