Skip to content

fix(sharebymail): do not escape the note mail heading twice - #65219

Open
skjnldsv wants to merge 1 commit into
masterfrom
fix/sharebymail-note-double-escape
Open

skjnldsv wants to merge 1 commit into
masterfrom
fix/sharebymail-note-double-escape

Conversation

@skjnldsv

@skjnldsv skjnldsv commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Summary

When someone adds a note to a mail share, the heading of the mail is escaped twice, so a name like Tom & Jerry shows up as Tom & Jerry. addHeading() already escapes, so the extra htmlspecialchars() goes.

Before After
before-note-heading after-note-heading

TODO

  • Test with a name containing & and '

Checklist

  • Code is properly formatted
  • Sign-off message is added to all commits
  • Tests are included
  • Screenshots before/after for front-end changes
  • Documentation has been updated or is not required
  • Backports requested where applicable
  • Labels added where applicable
  • Milestone added for target branch/version

AI (if applicable)

  • The content of this PR was partly or fully generated using AI

👾 This pull request was assisted by Claude Code, commits carry an Assisted-by trailer.

@skjnldsv
skjnldsv requested a review from a team as a code owner October 6, 2026 18:13
@skjnldsv
skjnldsv requested review from Altahrim, come-nc, provokateurin and salmart-dev and removed request for a team October 6, 2026 18:13
@skjnldsv skjnldsv added this to the Nextcloud 36 milestone Oct 6, 2026
@skjnldsv skjnldsv self-assigned this Oct 6, 2026
@skjnldsv
skjnldsv requested a review from CarlSchwan October 6, 2026 18:14
@skjnldsv
skjnldsv enabled auto-merge October 6, 2026 18:15
@skjnldsv
skjnldsv force-pushed the fix/sharebymail-note-double-escape branch from 305d300 to 61100ba Compare October 6, 2026 18:23
addHeading() already escapes its title, so a sharer display name
with & or ' showed up as & in the note mail.
DefaultShareProvider already passes the heading unescaped.

Assisted-by: ClaudeCode:claude-opus-5-5
Signed-off-by: John Molakvoæ <14975046+skjnldsv@users.noreply.github.com>
@skjnldsv
skjnldsv force-pushed the fix/sharebymail-note-double-escape branch from 61100ba to eaadcbc Compare October 7, 2026 09:34

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant