mirror of
https://github.com/TheFunny/TelegramTwitterMediaBot.git
synced 2026-09-23 23:32:05 +00:00
caption: escape URLs/handles in HTML captions
Post URLs and author URLs were interpolated raw into <a href> attributes (and the raw user URL from empty_fetched into caption text), so crafted links could break the HTML parse and fail the send with a 400. All attribute interpolations now use encode_double_quoted_attribute; text stays encode_text.
This commit is contained in:
@@ -162,7 +162,7 @@ async fn edit_message_handler(bot: &Bot, message: &Message) -> bool {
|
||||
};
|
||||
let link = format!(
|
||||
"<a href=\"{0}\">{1}</a>",
|
||||
edit.url,
|
||||
html_escape::encode_double_quoted_attribute(&edit.url),
|
||||
html_escape::encode_text(text)
|
||||
);
|
||||
let new_text = if edit.template.is_empty() {
|
||||
|
||||
Reference in New Issue
Block a user