From c5247f7021090358e8db70daa9ed09521e9f206a Mon Sep 17 00:00:00 2001 From: Christian Cleberg Date: Wed, 15 Jul 2026 19:29:57 -0500 Subject: fix: render code span contents literally processInline protected allowlisted HTML tags before it handled code spans, so a `` written inside backticks was carried through as a live tag and applied formatting instead of rendering as text. Every other inline pass ran against code span contents for the same reason, so `**x**` in backticks was emitted as bold. Protect code spans first with their contents escaped, which takes them out of reach of the tag, emphasis, and link passes. --- Hutch/Views/Repositories/ReadmeView.swift | 20 +++++++++++++------- 1 file changed, 13 insertions(+), 7 deletions(-) (limited to 'Hutch') diff --git a/Hutch/Views/Repositories/ReadmeView.swift b/Hutch/Views/Repositories/ReadmeView.swift index 720dff0..69d105b 100644 --- a/Hutch/Views/Repositories/ReadmeView.swift +++ b/Hutch/Views/Repositories/ReadmeView.swift @@ -371,8 +371,21 @@ nonisolated func processInline( ) -> String { var protectedFragments: [String: String] = [:] + + // Code spans render their contents literally, so they have to be taken out of + // the text before any later pass can treat those contents as markup — the tag + // pass below would otherwise promote an allowlisted `` into a live tag. var result = protectMatches( in: text, + pattern: #"`([^`]+)`"#, + protectedFragments: &protectedFragments + ) { match, nsText in + let code = nsText.substring(with: match.range(at: 1)) + return "\(escapeHTML(code))" + } + + result = protectMatches( + in: result, pattern: #"]*?>"#, protectedFragments: &protectedFragments ) { match, nsText in @@ -438,13 +451,6 @@ nonisolated func processInline( with: "$1", options: .regularExpression ) - // Inline code: `text` - result = result.replacingOccurrences( - of: #"`([^`]+)`"#, - with: "$1", - options: .regularExpression - ) - for (token, fragment) in protectedFragments { result = result.replacingOccurrences(of: token, with: fragment) } -- cgit v1.2.3