Repository navigation
[web] Render HTML in replace_lines diff output - #381
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
📝 WalkthroughWalkthroughHTML content in diff lines is now detected and routed through sanitizeHtmlAllowlist for security, while non-HTML content continues using markdownToHtml. The sanitized output replaces direct renderedContent references across all diff line types. Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~15 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing touches
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Motivation
replace_linesdiffs showed raw HTML tags instead of rendered rich text.read_pageso rich-text fragments display as HTML in tool results.Description
apps/web/src/components/ai/shared/chat/tool-calls/RichDiffRenderer.tsxto import and usesanitizeHtmlAllowlistfromcontent-utils.sanitizeHtmlAllowlist, falling back tomarkdownToHtmlfor plain text lines, and uses asafeRenderedContentvariable when assembling the diff HTML.DOMPurify.sanitizestep that was already present to ensure SSR safety and an extra sanitization pass beforedangerouslySetInnerHTML.Testing
pnpm --filter web exec eslint src/components/ai/shared/chat/tool-calls/RichDiffRenderer.tsx, which passed for the changed file.pnpm --filter web typecheck, which failed due to pre-existing workspace/module-resolution type errors unrelated to this change (several@pagespace/lib/*imports); the failure is environment-wide and not caused by this patch.ERR_EMPTY_RESPONSE), so no visual capture was produced.Codex Task
Summary by CodeRabbit