Skip to content

Improvement: #414 Add functional bracket auto-completion - #428

Merged
Jocs merged 3 commits into
marktext:masterfrom
enyaxu:improvement/414
Jul 27, 2018
Merged

Jocs merged 3 commits into
marktext:masterfrom
enyaxu:improvement/414

Conversation

@enyaxu

@enyaxu enyaxu commented Jul 19, 2018 •

Copy link
Copy Markdown
Contributor
Q A
Bug fix? no
New feature? yes
BC breaks? no
Deprecations? no
New tests added? not needed
Fixed tickets #414
License MIT

Description

Add functional bracket auto-completion for good experience.
kapture 2018-07-19 at 14 50 06

Please Review.

@Jocs
Jocs self-requested a review July 19, 2018 06:57
@Jocs

Jocs commented Jul 19, 2018

Copy link
Copy Markdown
Member

Great thanks for this PR, I'll review it latter.

@Jocs

Jocs commented Jul 23, 2018

Copy link
Copy Markdown
Member

@enyaxu I have one question:

if you enter *, it will be auto-complete to *<cursor>*, now if you enter another *, I think the result will be **<cursor>**. the same as _.

What's your opinions?

I am very sorry that I reply to you now because I am busy recently.

@enyaxu

enyaxu commented Jul 23, 2018 •

Copy link
Copy Markdown
Contributor Author

@jdoc sorry,I reply from my phone, I will comment later

@Jocs

Jocs commented Jul 23, 2018

Copy link
Copy Markdown
Member

@enyaxu I can not see some characters in your above comment.

@enyaxu

enyaxu commented Jul 24, 2018 •

Copy link
Copy Markdown
Contributor Author

@Jocs In Markdown world, use *<cursor>* or _<cursor>_ for emphasis format, and **<cursor>** or __<cursor>__ for strong format.
without * auto-completion, you write like this for emphasis format:

* --> *<cursor>* --> *some foo<cursor>*, now you need move <cursor> by mouse or keyboard -> to *some foo*<cursor>, with auto-completion you can just enter * for this. This also for strong format.

@Jocs

Jocs commented Jul 24, 2018

Copy link
Copy Markdown
Member

@enyaxu There is a little bug.

when I input *w<cursor>*, and press backspace to delete w. and it does not work.

@enyaxu

enyaxu commented Jul 25, 2018 •

Copy link
Copy Markdown
Contributor Author

@Jocs Ok, let me fix this.

@enyaxu

enyaxu commented Jul 25, 2018

Copy link
Copy Markdown
Contributor Author

@Jocs Fix it, please review.

@Jocs

Jocs commented Jul 26, 2018

Copy link
Copy Markdown
Member

I'll review it this evening. thanks.

@Jocs

Jocs commented Jul 26, 2018 •

Copy link
Copy Markdown
Member

@enyaxu

I found a problem, when I type *<cursor>*, then press the space, an bullet order list appears, but I can't type Chinese in the bullet order list. I don't know if this problem is caused by this PR, but before master is normal. I am also troubleshooting the cause.

Comment thread src/muya/lib/contentState/updateCtrl.js Outdated
/* eslint-enable no-useless-escape */
if (/\s/.test(event.data) && preInputChar === '*' && postInputChar === '*') {
text = text.substring(0, offset) + text.substring(offset + 1)
this.cursor = lastCursor = { start, end }

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why need add this line code?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is because last implement used particalRender function, now yes It not needed.

Comment thread src/muya/lib/contentState/updateCtrl.js Outdated
text = text.substring(0, offset) + text.substring(offset + 1)
}
}
block.text = text

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

the next 4 lines code need to put out of the if block. you can refer to the old codes.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

OK, I see it.

@Jocs

Jocs commented Jul 26, 2018

Copy link
Copy Markdown
Member

@enyaxu I find the reason that caused the Chinese problem, and you can see the comments.

@enyaxu

enyaxu commented Jul 26, 2018

Copy link
Copy Markdown
Contributor Author

@Jocs
Fixed Chinese type problem. Please review.

@Jocs

Jocs commented Jul 27, 2018

Copy link
Copy Markdown
Member

@enyaxu thank you again for this PR 👍

@Jocs
Jocs merged commit 486eb93 into marktext:master Jul 27, 2018
Jocs added a commit that referenced this pull request Jun 21, 2026
* chore(deps): bump dompurify to ^3.4.9 across desktop/muya/muyajs

Updates the HTML sanitizer from ^3.4.3/^3.4.5 to ^3.4.9 (resolves to
3.4.11), deduping the two installed versions (3.4.3 + 3.4.7) into one.
Clears Dependabot alerts #443/#451/#452/#453/#454/#455/#456.

MarkText calls DOMPurify.sanitize() only with string input and
RETURN_TRUSTED_TYPE: false (no IN_PLACE/RETURN_DOM/addHook/
SAFE_FOR_TEMPLATES), so none of these CVEs were reachable; the bump is
defense-in-depth for the editor's HTML sanitization path.

DOMPurify 3.4.8+ hardened cross-realm namespace validation, which the
happy-dom test environment does not satisfy: under happy-dom it strips
every element, even default-allowed tags like <p>/<h1>. Real
Chromium/Electron is unaffected (verified: jsdom, which matches production
DOM behavior, sanitizes correctly). Move the five DOMPurify-dependent muya
specs to the jsdom environment and declare jsdom as a muya devDependency.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

* chore(deps): bump happy-dom to ^20.8.9 in muya

Updates muya's vitest DOM test environment from ^15.11.7 to ^20.8.9
(resolves to 20.10.6). Clears Dependabot alerts
#426/#427/#428/#434/#437/#438 (2 critical "VM context escape / RCE",
4 high).

happy-dom is a devDependency used only as the unit-test DOM; it is never
bundled into the shipped app, and the muya suites run trusted fixtures, so
these CVEs were not reachable. The bump keeps the test toolchain current and
clears the critical badges. The full muya unit suite (143 files) passes on
20.x — the DOMPurify-dependent specs already moved to jsdom in the previous
commit.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

* chore(deps): update vite to patched 7.3.5 / 8.0.16

Bumps vite to the patched releases across the workspace (desktop ^7.3.5,
muya + muya-e2e ^8.0.16), updating the declared floors so installs can't
regress below the fix. Clears Dependabot alerts #441/#442/#447/#448
(server.fs.deny bypass + launch-editor NTLMv2 disclosure — both Windows
dev-server only; vite is build tooling, never shipped to users).

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

* chore(deps): pin transitive deps to patched versions via pnpm overrides

Adds range-scoped pnpm.overrides to force patched releases of the transitive
dependencies Dependabot flagged, while leaving unaffected older majors in
place (undici 6.x, esbuild 0.25.x, js-yaml 3.x):

  form-data   4.0.5      -> 4.0.6   (#450 CRLF injection)
  tmp         0.2.5      -> 0.2.6   (#411 path traversal)
  tar         7.5.15     -> 7.5.16  (#449 PAX file smuggling)
  ws          8.20.1     -> 8.21.0  (#444 memory-exhaustion DoS)
  undici      7.24/7.25  -> 7.28.0  (#457 SOCKS5 TLS bypass; keeps 6.25.0)
  esbuild     0.27/0.28.0-> 0.28.1  (#439 dev-server file read; keeps 0.25.x)
  @babel/core 7.29.0     -> 7.29.6  (#445 sourceMappingURL file read)
  js-yaml     4.1.1      -> 4.2.0   (#446 merge-key DoS; keeps 3.14.2)

All are build/test/website tooling reachable only on developer/CI machines,
never bundled into the shipped app. js-yaml 3.14.2 remains via the website's
gray-matter (no 3.x patch exists); it parses only trusted first-party
content, so #446 is not exploitable there and will be dismissed on GitHub.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]>
thimbleberrysystems pushed a commit to thimbleberrysystems/WordBird that referenced this pull request Jun 21, 2026
…ktext#428)

* Improvement: marktext#414 Add functional bracket auto-completion

* bugFix: marktext#414 wrong action with delete auto-complation function

* bugfix: Fixed bullet order list chinese input error
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants