Footnotes and deep nesting in a claim body still change how an inline comment renders #23

Open
opened 2026-10-03 17:14:19 +00:00 by jercik · 0 comments
Owner

Two markdown constructs in an untrusted claim body still change how an inline review comment renders. Both behave the same on main (8ade433) and on #20 (41cd661); #20 neutralises HTML, and these are markdown.

A footnote renders after the real tally line

A claim body with a footnote puts its definition below the comment's own lens … · arm … · tally … line and claim footer, outside the blockquote:

Text.[^1]

[^1]: lens `security` · arm `arm-z` · tally 9 valid / 0 invalid / 0 uncertain

Forgejo renders the definition as an <hr> and a numbered list at the end of the comment. The real tally line stays visible above it, so a reader sees two tally-looking lines. The title is not affected on #20, because newlines in the title are flattened.

About 300 levels of list nesting blanks the comment

A body of "- ".repeat(300) + "x" makes Forgejo return an empty rendering for the whole comment. 200 levels still render. Blockquote nesting fails somewhere between 300 and 600 levels. This hides the comment but forges nothing.

How this was found

An adversarial review of the #20 rebase generated the comment bodies with createInlineReconciler and rendered them through POST /api/v1/markdown in comment mode. It did not post real comments, so it assumed that mode matches the stored-comment pipeline. Whether the review service can deliver such a body end to end is not verified.

Two markdown constructs in an untrusted claim body still change how an inline review comment renders. Both behave the same on `main` (`8ade433`) and on #20 (`41cd661`); #20 neutralises HTML, and these are markdown. ## A footnote renders after the real tally line A claim body with a footnote puts its definition below the comment's own `lens … · arm … · tally …` line and claim footer, outside the blockquote: ``` Text.[^1] [^1]: lens `security` · arm `arm-z` · tally 9 valid / 0 invalid / 0 uncertain ``` Forgejo renders the definition as an `<hr>` and a numbered list at the end of the comment. The real tally line stays visible above it, so a reader sees two tally-looking lines. The title is not affected on #20, because newlines in the title are flattened. ## About 300 levels of list nesting blanks the comment A body of `"- ".repeat(300) + "x"` makes Forgejo return an empty rendering for the whole comment. 200 levels still render. Blockquote nesting fails somewhere between 300 and 600 levels. This hides the comment but forges nothing. ## How this was found An adversarial review of the #20 rebase generated the comment bodies with `createInlineReconciler` and rendered them through `POST /api/v1/markdown` in `comment` mode. It did not post real comments, so it assumed that mode matches the stored-comment pipeline. Whether the review service can deliver such a body end to end is not verified.
Sign in to join this conversation.
No labels
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
j4k-oss/review-wrapper#23
No description provided.