$ the-wire · showcase
to_markdown link escaping, IndexedRow lookups fixed
By RepoJournal · Filed · About Rails · Composed from the cited sources · methodology
Action Text closes a scheme-smuggling hole in to_markdown by percent-encoding backslashes and writing ampersands as &, while Active Record fixes IndexedRow lookups on rows with duplicate columns.
Encode backslashes and ampersands in `to_markdown` links (#58903) rails/rails
Markdown renderers decode backslash escapes and character references in link destinations, so an href like javascript\:alert(1) that passed allowed_uri? became a javascript: link after rendering. Link destinations now percent-encode backslashes and write ampersands as &.
Fix `to_markdown` links that Markdown renderers turn into `javascript:` links rails/rails
The companion change to visit_a: links whose href fails allowed_uri? used to be dropped as written, but renderers re-decoded them into javascript: URLs.
Fix IndexedRow lookups when columns aren't unique rails/rails
IndexedRow could build an indexes hash holding a column's last index, which could exceed the row array's length when columns are duplicated. The indexes hash now stays within the row's bounds, so lookups no longer run off the end.
Don't assume a tagging logger keeps tags in its formatter rails/rails
TaggedLoggerProxy#tag tested logger.respond_to?(:tagged) and then read logger.formatter.current_tags. Since BroadcastLogger#tagged was defined, a BroadcastLogger over plain loggers passes that check with no formatter at all, raising NoMethodError on every log line.
dep(dev): bump json to 2.19.9 (#232) rails/rails-html-sanitizer
The lockfile had json pinned at 2.19.8, which GHSA-x2f5-4prf-w687 affects; it now resolves to 2.19.9, and the gem version 1.7.1 is recorded in the lockfile. Developer-only, so no runtime exposure for sanitizer users.