fix(link-understanding): strip markdown links whose label contains brackets (#96476)

Merged via squash.

Prepared head SHA: 2d69ed259f
Co-authored-by: ly-wang19 <94427531+ly-wang19@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
Reviewed-by: @vincentkoc
This commit is contained in:
ly-wang19
2026-06-27 05:43:11 +08:00
committed by GitHub
parent a0e9ca1e95
commit d4a01e48bc
2 changed files with 13 additions and 1 deletions
+9
View File
@@ -20,6 +20,15 @@ describe("extractLinksFromMessage", () => {
expect(links).toEqual(["https://bare.example"]);
});
it("ignores markdown links whose label contains brackets", () => {
// The closing "]" inside the label must not break markdown stripping, otherwise
// the citation URL leaks out as a bare link (with a stray trailing ")").
const links = extractLinksFromMessage(
"Check [my notes [v2]](https://internal.example/doc) for details",
);
expect(links).toStrictEqual([]);
});
it("blocks 127.0.0.1", () => {
const links = extractLinksFromMessage("http://127.0.0.1/test https://ok.test");
expect(links).toEqual(["https://ok.test"]);
+4 -1
View File
@@ -3,7 +3,10 @@ import { isBlockedHostnameOrIp } from "../infra/net/ssrf.js";
import { DEFAULT_MAX_LINKS } from "./defaults.js";
// Remove markdown link syntax so only bare URLs are considered.
const MARKDOWN_LINK_RE = /\[[^\]]*]\((https?:\/\/\S+?)\)/gi;
// The link-text portion allows "]" that is not the closing "](" boundary so
// markdown links whose label contains brackets (e.g. "[my notes [v2]](...)")
// are still stripped instead of leaking their URL to BARE_LINK_RE.
const MARKDOWN_LINK_RE = /\[(?:[^\]]|](?!\())*]\((https?:\/\/\S+?)\)/gi;
const BARE_LINK_RE = /https?:\/\/\S+/gi;
function stripMarkdownLinks(message: string): string {