fix(ui): escape Markdown special characters in tooltip user values#406
Conversation
Prevents display corruption when git config values contain pipe characters, Markdown formatting syntax, HTML tags, or newlines. - Add escapeMarkdownInline() in markdownEscape.ts (pure function, no VS Code dependency) covering: \ * _ ` [ ] < > | - Apply to all user-supplied values in buildTooltip() and buildMismatchTooltip() - Add 15 unit tests + 1 E2E test for pipe escape in mismatch table 🖥️ IDE: [Cursor](https://cursor.sh) 🔌 Extension: [Claude Code](https://claude.ai/download) Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> Model-Raw: claude-opus-4-6
🐰 Mimi's Validation Report ✅All checks are looking good! Great job! 🎉 ⏳ Some checks are still running. I will keep watching!
This report was carefully prepared by nullvariant-mimi[bot] |
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Snapshot WarningsEnsure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice. Scanned FilesNone |
🦥 Slow's Code Review 😩...yawn... Do I really have to review this?
| Split it up... reading long files is exhausting.
This review was reluctantly filed by nullvariant-slow[bot] |
🕊️ Ciel's Mediation 🌤️*~~ floating down from the clouds ~~ The zoo seems a bit noisy today...* 2 zoo members have reviewed this PR.
⚖️ The zoo has mixed opinions. Some are concerned, some are fine with it. Please review each comment carefully and make the final call.
This mediation was peacefully delivered by nullvariant-ciel[bot] |
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |



Summary
escapeMarkdownInline()pure function inmarkdownEscape.tsto escape Markdown special characters (\,*,_,`,[,],<,>,|) and sanitize newlines (\n→ space,\r→ removed)buildTooltip()(identity name, description, email, SSH host, SSH key, GPG key) andbuildMismatchTooltip()(expected/actual mismatch values)Test plan
npx tsc --noEmitpassesnpm run test)markdownEscape.ts: 100% all metrics)🤖 Generated with Claude Code