FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

fix(sanitize): preserve visible Markdown content by SamMorrowDrums · Pull Request #3177 · github/github-mcp-server · GitHub

fix(sanitize): preserve visible Markdown content - #3177

Draft
SamMorrowDrums wants to merge 1 commit into
mainfrom
sammorrowdrums-sanitization-robustness
Draft

fix(sanitize): preserve visible Markdown content#3177
SamMorrowDrums wants to merge 1 commit into
mainfrom
sammorrowdrums-sanitization-robustness

Conversation

Copy link
Copy Markdown
Collaborator

Summary

Fix the sanitizer boundary so reading Markdown/code-bearing GitHub content no longer silently deletes or truncates source that may later be written back.

  • keep the strict HTML policy for short metadata such as titles
  • add a Markdown-aware content policy for bodies, comments, reviews, release notes, status updates, and commit messages
  • preserve inline, fenced, and indented code byte-for-byte where syntax is meant to be literal
  • make render-hidden Markdown constructs visible instead of deleting their contents
  • neutralize literal and entity-encoded invisible controls, hidden fence metadata, HTML comments/blocks, unused metadata, GitHub math, footnotes, images, and non-visible link labels
  • apply the same policy to direct sub-issue response paths
  • retain allocation-free handling for ordinary clean text and bound adversarial fixed-point work

Security boundary

Valid non-empty HTTP/HTTPS/mailto/relative link destinations remain functional because GitHub exposes them on hover/click. Non-URL-like, titled, image, empty-label, full-reference, unused, and duplicate forms are made visible.

Rich content removes variation selectors and zero-width joiners rather than trying to validate the full Unicode variation/grapheme registries. Visible base characters remain, but presentation may change. GitHub-rendered diagram/math fence types are returned as visible source rather than opaque rendered output.

Validation

  • script/lint
  • script/test
  • script/licenses-check
  • repeated 30-second FuzzContentIsIdempotent runs covering idempotence, rendered hidden-rune safety, hidden Markdown constructs, and adversarial nesting
  • dedicated security and correctness review passes during implementation

Fixes #2202
Fixes #3165

Separate short metadata sanitization from a Markdown-aware content policy.
Keep code faithful, expose render-hidden constructs, and prevent sanitized
read-modify-write cycles from silently deleting issue and pull request data.

Refs #2202
Refs #3165

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 69c5ab30-9815-4c07-8385-11a206e68f66
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant


Back | FazBrowse Home | New Git URL