fix(sanitize): preserve visible Markdown content - #3177
Draft
SamMorrowDrums wants to merge 1 commit into
Draft
Conversation
Separate short metadata sanitization from a Markdown-aware content policy. Keep code faithful, expose render-hidden constructs, and prevent sanitized read-modify-write cycles from silently deleting issue and pull request data. Refs #2202 Refs #3165 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 69c5ab30-9815-4c07-8385-11a206e68f66
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fix the sanitizer boundary so reading Markdown/code-bearing GitHub content no longer silently deletes or truncates source that may later be written back.
Security boundary
Valid non-empty HTTP/HTTPS/mailto/relative link destinations remain functional because GitHub exposes them on hover/click. Non-URL-like, titled, image, empty-label, full-reference, unused, and duplicate forms are made visible.
Rich content removes variation selectors and zero-width joiners rather than trying to validate the full Unicode variation/grapheme registries. Visible base characters remain, but presentation may change. GitHub-rendered diagram/math fence types are returned as visible source rather than opaque rendered output.
Validation
script/lintscript/testscript/licenses-checkFuzzContentIsIdempotentruns covering idempotence, rendered hidden-rune safety, hidden Markdown constructs, and adversarial nestingFixes #2202
Fixes #3165