Repository navigation
fix: escape filename urls in html report href attributes - #2227
Merged
Merged
Conversation
Contributor
Author
|
any update? |
nedbat
reviewed
Aug 2, 2026
| return t.replace("&", "&").replace("<", "<") | ||
|
|
||
|
|
||
| def escape_url(url: str) -> str: |
Member
There was a problem hiding this comment.
Somehow I missed html.escape in the stdlib which can be used for both URLs and text. We don't need either escape or escape_url it seems.
Contributor
Author
There was a problem hiding this comment.
Done, dropped both helpers and registered stdlib html.escape as the escape filter. It also escapes quotes and > in text positions, so a handful of gold files and expected strings picked up "/' entities; updated those to match. test_html.py is green.
Per review, drop the custom escape and escape_url helpers in favor of html.escape from the stdlib. It also escapes quotes and > in text positions, so the gold files and expected strings are updated to match.
Member
|
I fixed the two failures |
Member
|
This is now released as part of coverage 7.15.4. |
1 task
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The HTML report turns each source file name into a page URL with flat_rootname and drops it into the href of the index rows, region links, and prev/next nav without escaping. A measured file whose name contains a double quote (legal on POSIX, and what you get running coverage over a tree you don't control) closes the href early, so the rest of the name becomes live attributes on the link, like an onmouseover handler that runs in the viewer's browser.
escape() is only meant for text and doesn't touch quotes, so this adds a small escape_url filter that entity-escapes the URL and applies it at each href in index.html and pyfile.html. Escaping in the template keeps the on-disk page names intact while the emitted links, which browsers decode back to the real names, stay valid.