mirror of
https://github.com/TheFunny/TelegramTwitterMediaBot.git
synced 2026-09-23 23:32:05 +00:00
caption: escape URLs/handles in HTML captions
Post URLs and author URLs were interpolated raw into <a href> attributes (and the raw user URL from empty_fetched into caption text), so crafted links could break the HTML parse and fail the send with a 400. All attribute interpolations now use encode_double_quoted_attribute; text stays encode_text.
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
use super::model::{IllustrationModel, TypeModel};
|
||||
use crate::media::Media;
|
||||
use crate::site::{FetchError, Fetched};
|
||||
use html_escape::encode_text;
|
||||
use html_escape::{encode_double_quoted_attribute, encode_text};
|
||||
use regex::Regex;
|
||||
use std::sync::LazyLock;
|
||||
|
||||
@@ -48,9 +48,9 @@ impl Illustration {
|
||||
pub fn caption(&self) -> String {
|
||||
format!(
|
||||
"<a href=\"{url}\">{title}</a> / <a href=\"{author_url}\">{author}</a>\n{tags}",
|
||||
url = self.url(),
|
||||
url = encode_double_quoted_attribute(&self.url()),
|
||||
title = encode_text(&self.title),
|
||||
author_url = self.author_url(),
|
||||
author_url = encode_double_quoted_attribute(&self.author_url()),
|
||||
author = encode_text(&self.author),
|
||||
tags = encode_text(
|
||||
&self
|
||||
|
||||
Reference in New Issue
Block a user