fix(chat): do not handle chat usernames as html escaped. Closes #3743

This commit is contained in:
Gabe Kangas
2025-03-10 21:12:09 -07:00
parent 406545f1a2
commit e088520d46
+18
View File
@@ -4,6 +4,7 @@ import (
"strings"
"github.com/microcosm-cc/bluemonday"
"golang.org/x/net/html"
)
// StripHTML will strip HTML tags from a string.
@@ -17,6 +18,7 @@ func StripHTML(s string) string {
func MakeSafeStringOfLength(s string, length int) string {
newString := s
newString = StripHTML(newString)
newString = htmlUnescape(newString)
// Convert utf-8 string into Unicode code points.
codePoints := []rune(newString)
@@ -31,3 +33,19 @@ func MakeSafeStringOfLength(s string, length int) string {
return newString
}
func htmlUnescape(input string) string {
token := html.NewTokenizer(strings.NewReader(input))
var output strings.Builder
for {
tt := token.Next()
switch tt {
case html.ErrorToken:
return output.String()
case html.TextToken:
text := string(token.Text())
output.WriteString(text)
}
}
}