Skip to content

fix: escape filename urls in html report href attributes - #2227

Merged
nedbat merged 3 commits into
coveragepy:mainfrom
rajath201:html-href-escape
Aug 4, 2026
Merged

nedbat merged 3 commits into
coveragepy:mainfrom
rajath201:html-href-escape

Conversation

@rajath201

Copy link
Copy Markdown
Contributor

The HTML report turns each source file name into a page URL with flat_rootname and drops it into the href of the index rows, region links, and prev/next nav without escaping. A measured file whose name contains a double quote (legal on POSIX, and what you get running coverage over a tree you don't control) closes the href early, so the rest of the name becomes live attributes on the link, like an onmouseover handler that runs in the viewer's browser.

escape() is only meant for text and doesn't touch quotes, so this adds a small escape_url filter that entity-escapes the URL and applies it at each href in index.html and pyfile.html. Escaping in the template keeps the on-disk page names intact while the emitted links, which browsers decode back to the real names, stay valid.

@rajath201

Copy link
Copy Markdown
Contributor Author

any update?

Comment thread coverage/html.py Outdated
return t.replace("&", "&amp;").replace("<", "&lt;")


def escape_url(url: str) -> str:

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Somehow I missed html.escape in the stdlib which can be used for both URLs and text. We don't need either escape or escape_url it seems.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done, dropped both helpers and registered stdlib html.escape as the escape filter. It also escapes quotes and > in text positions, so a handful of gold files and expected strings picked up &quot;/&#x27; entities; updated those to match. test_html.py is green.

rajath201 and others added 2 commits August 4, 2026 23:46
Per review, drop the custom escape and escape_url helpers in favor of
html.escape from the stdlib. It also escapes quotes and > in text
positions, so the gold files and expected strings are updated to match.
@nedbat

nedbat commented Aug 4, 2026

Copy link
Copy Markdown
Member

I fixed the two failures

@nedbat
nedbat merged commit a7a2c15 into coveragepy:main Aug 4, 2026
72 checks passed
@nedbat

nedbat commented Aug 6, 2026

Copy link
Copy Markdown
Member

This is now released as part of coverage 7.15.4.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants