Skip to content

[stable33] fix(files): don't expose WebDAV XML-attribute artifacts as DOM attributes#3289

Open
backportbot[bot] wants to merge 1 commit into
stable33from
backport/3225/stable33
Open

[stable33] fix(files): don't expose WebDAV XML-attribute artifacts as DOM attributes#3289
backportbot[bot] wants to merge 1 commit into
stable33from
backport/3225/stable33

Conversation

@backportbot

@backportbot backportbot Bot commented Jul 20, 2026

Copy link
Copy Markdown

…utes

genFileInfo() flattens every DAV property and runs camelcase() on each
key. Since Nextcloud 33, a file's nc:system-tags property contains
<nc:system-tag> elements that carry XML attributes (can-assign, id,
user-visible, ...). The WebDAV parser represents those attributes with a
leading "@", and camelcase() preserves it, so genFileInfo produced keys
such as "@canAssign". When the resulting object is bound via v-bind in
Viewer.vue, Vue calls setAttribute("@canAssign", ...), which throws
"InvalidCharacterError: Invalid qualified name" on Firefox and Safari
(Chrome silently ignores it). The result is that tagged office files
cannot be opened in those browsers.

Skip the structured system-tags subtree (it is not scalar file metadata)
and, as a defensive backstop, drop any camelCased key that still starts
with "@", so XML-attribute artifacts never reach the DOM.

Ref: nextcloud/richdocuments#5490

Assisted-by: ClaudeCode:Opus-4.8
Signed-off-by: Christoph Schaefer <christoph.schaefer@nextcloud.com>
@backportbot
backportbot Bot requested review from chrip and skjnldsv July 20, 2026 15:17
@backportbot backportbot Bot added bug Something isn't working 3. to review Waiting for reviews feedback-requested labels Jul 20, 2026
@backportbot backportbot Bot added this to the Nextcloud 33.0.7 milestone Jul 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews bug Something isn't working feedback-requested

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant