Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions CHANGES.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@
- [pull #720] Add `wiki-links` extra for `[[Page Name]]` style links (#221)
- [pull #722] Harden URL safety checks and sanitization in safe mode (#721)
- [pull #728] Fix XSS from zero-padded colon entities in link URLs (#726)
- [pull #735] Fix `smarty-pants` extra converting quotes inside inline HTML tags and comments (#150)


## python-markdown2 2.5.5
Expand Down
19 changes: 14 additions & 5 deletions lib/markdown2.py
Original file line number Diff line number Diff line change
Expand Up @@ -4167,6 +4167,18 @@ def run(self, text: str):
<http://code.google.com/p/python-markdown2/issues/detail?id=42> for a
discussion of some diversion from the original SmartyPants.
"""
# Swap out inline HTML tags and comments so their attribute quotes
# and `--` are left alone (#150). The placeholders are non-space, so
# the quote rules see the same context around them as before.
tags = {}

def hash_tag(match: re.Match[str]) -> str:
key = _hash_text(match.group(0))
tags[key] = match.group(0)
return key

text = self.md._sorta_html_tokenize_re.sub(hash_tag, text)

if "'" in text: # guard for perf
text = self.contractions(text)
text = self._opening_single_quote_re.sub("&#8216;", text)
Expand All @@ -4182,11 +4194,8 @@ def run(self, text: str):
text = text.replace(" . . . ", "&#8230;")
text = text.replace(". . .", "&#8230;")

# TODO: Temporary hack to fix https://github.com/trentm/python-markdown2/issues/150
if "footnotes" in self.md.extras and "footnote-ref" in text:
# Quotes in the footnote back ref get converted to "smart" quotes
# Change them back here to ensure they work.
text = text.replace('class="footnote-ref&#8221;', 'class="footnote-ref"')
for key, tag in tags.items():
text = text.replace(key, tag)

return text

Expand Down
5 changes: 5 additions & 0 deletions test/tm-cases/smarty_pants_html_attributes_issue150.html
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
<p>An inline image <img src="/path/to/img.png" alt="Alt Text"> keeps its attributes.</p>

<p>A raw <a href="https://example.com/" title='Example'>link</a> and <span class="note">a &#8220;quoted&#8221; word</span>.</p>

<p>An inline <!-- HTML -- comment --> is left alone, but &#8220;quotes&#8221; and dashes &#8211; outside it still change.</p>
1 change: 1 addition & 0 deletions test/tm-cases/smarty_pants_html_attributes_issue150.opts
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
{"extras": ["smarty-pants"]}
5 changes: 5 additions & 0 deletions test/tm-cases/smarty_pants_html_attributes_issue150.text
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
An inline image <img src="/path/to/img.png" alt="Alt Text"> keeps its attributes.

A raw <a href="https://example.com/" title='Example'>link</a> and <span class="note">a "quoted" word</span>.

An inline <!-- HTML -- comment --> is left alone, but "quotes" and dashes -- outside it still change.