fix: sanitize hyperlink OSC output (#29) (thanks @mafulafunk)

This commit is contained in:
Peter Steinberger
2026-01-11 11:11:21 +00:00
parent 837b09fcad
commit 0a4699711f
3 changed files with 11 additions and 1 deletions
+1
View File
@@ -4,6 +4,7 @@
### Fixed
- macOS cookie extraction now supports Brave keychain storage (#40) — thanks @gakonst.
- Terminal hyperlinks now sanitize control characters before emitting OSC 8 sequences (#29) — thanks @mafulafunk.
- Following/followers pagination now guards repeat cursors and standardizes JSON output (#28) — thanks @malpern.
- Lists GraphQL feature flags updated to prevent 400s (#27) — thanks @zheli.
- Likes pagination now follows cursors and avoids stalling on duplicate pages (#12) — thanks @titouv.
+3 -1
View File
@@ -106,8 +106,10 @@ export function hyperlink(url: string, text?: string, cfg?: OutputConfig): strin
if (!cfg?.hyperlinks) {
return displayText;
}
const safeUrl = url.replaceAll('\x1b', '').replaceAll('\x07', '');
const safeText = displayText.replaceAll('\x1b', '').replaceAll('\x07', '');
// OSC 8 hyperlink: \x1b]8;;URL\x07TEXT\x1b]8;;\x07
return `\x1b]8;;${url}\x07${displayText}\x1b]8;;\x07`;
return `\x1b]8;;${safeUrl}\x07${safeText}\x1b]8;;\x07`;
}
export function formatTweetUrlLine(tweetId: string, cfg: OutputConfig): string {
+7
View File
@@ -111,4 +111,11 @@ describe('output', () => {
expect(result).toContain('Click here');
expect(result).toContain('\x1b]8;;https://x.com/test\x07');
});
it('hyperlink strips OSC control characters from url and text', () => {
const cfg = { plain: false, emoji: true, color: true, hyperlinks: true };
const result = hyperlink('https://x.com/\u001btest\u0007', 'Hi\u001b\u0007', cfg);
expect(result).not.toContain('\u001btest\u0007');
expect(result).not.toContain('Hi\u001b\u0007');
});
});