Sitelet https://web.archive.org/web/20230319185610/https://github.com/github/vscode-codeql/issues/1104
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Square brackets in alert messages are not rendered correctly #1104

Open
henrymercer opened this issue Jan 27, 2022 · 1 comment
Open

Square brackets in alert messages are not rendered correctly #1104

henrymercer opened this issue Jan 27, 2022 · 1 comment
Labels
bug Something isn't working VSCode

Comments

@henrymercer
Copy link
Contributor

Describe the bug
Square brackets in alert messages [ and ] are rendered as \[ and \] respectively.

Version
CodeQL extension version: 1.5.10
CodeQL CLI version: 2.7.5
Platform: darwin x64

To reproduce
Run the following query on a JavaScript (for instance) project:

/**
 * @kind alert
 */
import javascript
select any(File f), "[] test"

Right click the query in the query history view and select "View Alerts (SARIF)". Observe that the square brackets are correctly escaped as \\[ and \\] per the SARIF spec:

Literal square brackets ("[" and "]") in the link text of a plain text message SHALL be escaped with a backslash (""). Since JSON itself treats the backslash as an escape character, the backslash SHALL be doubled.

Observe that the square brackets are not correctly escaped in the alert message:

image

Expected behavior
The alert message should be "[] test"

@henrymercer henrymercer added the bug Something isn't working label Jan 27, 2022
@aeisenberg
Copy link
Contributor

Thanks for raising this. I see that the raw results are rendered correctly. So, the SARIF is correct, it's just that our handling of the JSON needs to remove the \\ before displaying.

According to the spec, we should be handling unescaped [..] as a link. I don't think we're doing this either.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working VSCode
Projects
None yet
Development

No branches or pull requests

2 participants