Skip to content

Link with custom protocoll does not work #4356

Description

@bennoremec

Description

Link with custom protocoll does not work

Minimal Reprouducible Markdown Example (or Steps)

For example

  1. Create Link sambesi://localhost/node/11164
  2. Click on Link

Stack Trace

TypeError: Cannot read properties of null (reading 'length')
    at Proxy.FORMAT_LINK_CLICK (file:///C:/Users/inb/AppData/Local/Programs/MarkText/resources/app.asar/out/renderer/assets/index-DgUR2NkZ.js:86727:22)
    at Proxy.wrappedAction (file:///C:/Users/inb/AppData/Local/Programs/MarkText/resources/app.asar/out/renderer/assets/index-DgUR2NkZ.js:13893:19)
    at Object.jumpClick (file:///C:/Users/inb/AppData/Local/Programs/MarkText/resources/app.asar/out/renderer/assets/index-DgUR2NkZ.js:150691:19)
    at LinkTools.selectItem (file:///C:/Users/inb/AppData/Local/Programs/MarkText/resources/app.asar/out/renderer/assets/index-DgUR2NkZ.js:149183:22)
    at Object.click (file:///C:/Users/inb/AppData/Local/Programs/MarkText/resources/app.asar/out/renderer/assets/index-DgUR2NkZ.js:149160:18)
    at invokeHandler (file:///C:/Users/inb/AppData/Local/Programs/MarkText/resources/app.asar/out/renderer/assets/index-DgUR2NkZ.js:92215:13)
    at handleEvent (file:///C:/Users/inb/AppData/Local/Programs/MarkText/resources/app.asar/out/renderer/assets/index-DgUR2NkZ.js:92226:5)
    at HTMLLIElement.handler (file:///C:/Users/inb/AppData/Local/Programs/MarkText/resources/app.asar/out/renderer/assets/index-DgUR2NkZ.js:92231:5)

Version

MarkText: v0.19.0
Operating system: Windows_NT x64 10.0.26200 (win32)

Activity

  1. FurkaanBoraa commented on Jun 12, 2026

    @FurkaanBoraa
    Contributor

    Reproduced on macOS (Apple Silicon) against the latest develop (64e590c), so this is not Windows-specific. Steps: open a document containing [sambesi://localhost/node/11164](sambesi://localhost/node/11164), hover the link, and click the jump button in the popover — the renderer throws the same TypeError: Cannot read properties of null (reading 'length') in FORMAT_LINK_CLICK.

    Root cause: muya's sanitizeHyperlink (DOMPurify's protocol allowlist) strips the sambesi:// href at render time, so the link popover captures href: null, and the jump handler forwards that to FORMAT_LINK_CLICK, which read data.href.length without a guard.

    There are two separate things in this issue:

    1. The crash — fixed in fix: #4356 crash when using the link popover on a link with an unsupported protocol #4473: the popover no longer offers "jump" when there is no usable href, and the store guards null defensively.

    2. Custom protocols not opening at all — this appears deliberate and predates the engine rewrite: the main-process mt::format-link-click handler only opens http(s) URLs and explicitly swallows other schemes (// Prevent other URLs. in packages/desktop/src/main/menu/actions/file.ts). Opening arbitrary schemes via shell.openExternal is a real security surface, so I left that behavior unchanged in the PR. If supporting custom protocols (perhaps behind a confirmation prompt or a preference) is wanted, I would be happy to work on it as a follow-up once there is maintainer guidance on the desired approach.

  2. FurkaanBoraa commented on Jun 12, 2026

    @FurkaanBoraa
    Contributor

    For maintainers triaging this: there are now two open PRs on this issue with different scopes. #4416 (earlier) proposes actually opening custom-protocol links via shell.openExternal with a denylist of unsafe schemes. My #4473 is narrower — it only fixes the crash (the popover stops offering "jump" when the sanitizer stripped the href, plus a null guard in the store) and deliberately leaves the existing http(s)-only policy unchanged, treating "should custom schemes open at all" as a maintainer decision. The two PRs conflict textually (both touch store/editor.ts and add test/e2e/issue-4356.spec.ts), so whichever direction is preferred, I'm happy to rebase or adapt mine.

  3. Jocs commented on Jun 15, 2026

    @Jocs
    Member

    Many thanks to @FurkaanBoraa for investigating and fixing the issue. #4414 still seems to be in draft state. I will review it together once this PR is ready.

  4. added 2 commits that reference this issue on Jun 17, 2026
    4ec36fb
    aa86971
  5. added a commit that references this issue on Jun 21, 2026
    cd7c0df
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    🐛 bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions