From 73ef090b9e7659926a32a7a287f0e003da331c3c Mon Sep 17 00:00:00 2001 From: Kevin Papst Date: Wed, 19 Oct 2022 21:17:49 +0200 Subject: [PATCH] fix several rendering issues in markdown (#3588) - fix double escaping of html entities: " instead of " - fix table is missing css class "table" - fix quotes are not rendered --- src/Twig/Runtime/MarkdownExtension.php | 4 ++-- src/Twig/RuntimeExtensions.php | 4 ++-- src/Utils/ParsedownExtension.php | 15 ++++++++++++++- tests/Twig/RuntimeExtensionsTest.php | 2 -- 4 files changed, 18 insertions(+), 7 deletions(-) diff --git a/src/Twig/Runtime/MarkdownExtension.php b/src/Twig/Runtime/MarkdownExtension.php index 3c4d72a9..5d8c763c 100644 --- a/src/Twig/Runtime/MarkdownExtension.php +++ b/src/Twig/Runtime/MarkdownExtension.php @@ -63,7 +63,7 @@ final class MarkdownExtension implements RuntimeExtensionInterface if ($this->isMarkdownEnabled()) { $content = $this->markdown->toHtml($content); } elseif ($fullLength) { - $content = '

' . nl2br($content) . '

'; + $content = '

' . nl2br(htmlspecialchars($content)) . '

'; } return $content; @@ -115,7 +115,7 @@ final class MarkdownExtension implements RuntimeExtensionInterface return $this->markdown->toHtml($content); } - return nl2br($content); + return nl2br(htmlspecialchars($content)); } /** diff --git a/src/Twig/RuntimeExtensions.php b/src/Twig/RuntimeExtensions.php index b2c14760..7af602a1 100644 --- a/src/Twig/RuntimeExtensions.php +++ b/src/Twig/RuntimeExtensions.php @@ -45,8 +45,8 @@ class RuntimeExtensions extends AbstractExtension { return [ new TwigFilter('md2html', [MarkdownExtension::class, 'markdownToHtml'], ['pre_escape' => 'html', 'is_safe' => ['html']]), - new TwigFilter('desc2html', [MarkdownExtension::class, 'timesheetContent'], ['pre_escape' => 'html', 'is_safe' => ['html']]), - new TwigFilter('comment2html', [MarkdownExtension::class, 'commentContent'], ['pre_escape' => 'html', 'is_safe' => ['html']]), + new TwigFilter('desc2html', [MarkdownExtension::class, 'timesheetContent'], ['is_safe' => ['html']]), + new TwigFilter('comment2html', [MarkdownExtension::class, 'commentContent'], ['is_safe' => ['html']]), new TwigFilter('comment1line', [MarkdownExtension::class, 'commentOneLiner'], ['pre_escape' => 'html', 'is_safe' => ['html']]), new TwigFilter('colorize', [ThemeExtension::class, 'colorize']), ]; diff --git a/src/Utils/ParsedownExtension.php b/src/Utils/ParsedownExtension.php index c68f689c..095265d5 100644 --- a/src/Utils/ParsedownExtension.php +++ b/src/Utils/ParsedownExtension.php @@ -18,7 +18,7 @@ class ParsedownExtension extends \Parsedown /** * Overwritten to prevent # to show up as headings for two reasons: - * - Hashes are often used to cross link issues in other systems + * - Hashes are often used to cross-link issues in other systems * - Headings should not occur in time record listings */ protected $BlockTypes = [ @@ -146,4 +146,17 @@ class ParsedownExtension extends \Parsedown return $text; } + + protected function blockTable($Line, array $Block = null) + { + $Block = parent::blockTable($Line, $Block); + + if (\is_null($Block)) { + return; + } + + $Block['element']['attributes']['class'] = 'table'; + + return $Block; + } } diff --git a/tests/Twig/RuntimeExtensionsTest.php b/tests/Twig/RuntimeExtensionsTest.php index 4aaff168..3d388d45 100644 --- a/tests/Twig/RuntimeExtensionsTest.php +++ b/tests/Twig/RuntimeExtensionsTest.php @@ -80,12 +80,10 @@ class RuntimeExtensionsTest extends TestCase $found_md2html = true; break; case 'desc2html': - self::assertEquals('html', $filters[1]->getPreEscape()); self::assertEquals(['html'], $filters[1]->getSafe(new Node())); $found_desc2html = true; break; case 'comment2html': - self::assertEquals('html', $filters[2]->getPreEscape()); self::assertEquals(['html'], $filters[2]->getSafe(new Node())); $found_comment2html = true; break;