Fix double-escaped "<" in RSS item descriptions - #245
Merged
Conversation
The description field pre-escaped '<' in the raw commit message before
running it through create_anchors()/replaceIDs()/nl2br(), and the whole
description was then escaped again via escape() a few lines below when
assembling the RSS item. escape() also converts '&' to '&', so the
'&' produced by the pre-escape's own '<' got escaped a second time,
turning it into '&lt;'. Any RSS reader decoding entities once (as
they all do) would then show the literal text "<" instead of a
real "<" character in the description -- while every other character
the message could contain ('>', '&', '"', ''') passed through the
single, correct escape() call unaffected.
Drop the pre-escape and let the raw message flow into escape() exactly
once, like every other field assembled into $description.
michael-o
force-pushed
the
fix-rss-description-double-escape
branch
from
September 10, 2026 15:44
db01796 to
cafd2d0
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The description field pre-escaped '<' in the raw commit message before running it through create_anchors()/replaceIDs()/nl2br(), and the whole description was then escaped again via escape() a few lines below when assembling the RSS item. escape() also converts '&' to '&', so the '&' produced by the pre-escape's own '<' got escaped a second time, turning it into '<'. Any RSS reader decoding entities once (as they all do) would then show the literal text "<" instead of a real "<" character in the description -- while every other character the message could contain ('>', '&', '"', ''') passed through the single, correct escape() call unaffected.
Drop the pre-escape and let the raw message flow into escape() exactly once, like every other field assembled into $description.