Escape HTML special characters in HTMLFormatter#274
Merged
Conversation
Contributor
Author
|
@d-ronnqvist Can you review this pr? |
d-ronnqvist
reviewed
Jun 5, 2026
Contributor
Author
|
@d-ronnqvist Thanks for the review. I've updated the escaping helper to only escape &, <, and >, since it's used for text and code content rather than attribute values. I also removed the unrelated link title change to keep the PR focused on the HTML escaping fix, so there is no longer any untested behavior being introduced. |
d-ronnqvist
approved these changes
Jun 8, 2026
d-ronnqvist
left a comment
Contributor
There was a problem hiding this comment.
Thanks for fixing this issue.
Contributor
|
@swift-ci please test |
Contributor
Author
|
@d-ronnqvist I have added the required comment. Can you run the CI again? |
Contributor
|
Thanks. That comment looks great |
Contributor
|
@swift-ci please test |
jackbolen
added a commit
to jackbolen/swift-markdown
that referenced
this pull request
Jul 19, 2026
Upstream swiftlang#274 (visitText/visitInlineCode/visitCodeBlock escape &<> through String.htmlEscaped()) and swiftlang#280 (visitHeading descends into nested markup) land byte-for-byte so the next upstream merge is clean. Fork delta on top: attribute positions — link href, image src/title, footnote ids/hrefs, and data-attributes — route through a quote-escaping attribute wrapper, since upstream's 3-character text helper cannot serve a double-quoted attribute; data-attributes drops its invalid backslash-escaped quote for ". Math text moves onto htmlEscaped() (a quote needs no escape in text position).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bug/issue #, if applicable: Fixes #264
Summary
The HTML formatter previously emitted text, inline code, and code block contents without escaping HTML special characters. As a result, markdown containing escaped entities such as:
could be rendered as HTML that browsers interpret as an actual tag rather than displaying the text . This change escapes &, <, and > when rendering text, inline code, and code block contents in HTMLFormatter. Raw HTML nodes (HTMLBlock and InlineHTML) continue to be emitted unchanged.
Dependencies
N/A
Testing
Regression tests have been added to verify correct rendering for:
Steps:
Checklist
Make sure you check off the following items. If they cannot be completed, provide a reason.
./bin/testscript and it succeeded