Cite with markdown links and stop rendering HTML in the chat - #307
Merged
Merged
Conversation
The chat rendered HTML because answers cited with <a href> anchors, and that let any markup that reached a message run in the reader's browser (review, area 1b). Citations are now markdown links and unsafe_allow_html is false, which closes the whole class. - Five prompts ask for [Name](URL) instead of <a href="URL">Name</a>. Measured on the answer sweep's 16 questions, twice each: cited answers 24/32 before and after; HTML anchors 24 -> 0; markdown links 7 -> 24; Sources heading 24 -> 24. Full sweep 16/16. - The search page's answer stream strips markdown links to their labels, as it strips anchors (kept, in case one slips through). - Chainlit's renderer includes remark-directive, which read the ':p25' in 'CDK5:p25' as markup and dropped it. Anchors had hidden this in link labels; prose always had it. Directive-shaped colons are now escaped in finished answers and wherever names are written into chat messages. Checked in a browser: citations render as clickable links, no markdown or HTML syntax shows as text, 'CDK5:p25' stays intact; with the handoff escaping removed and HTML off, injected markup still renders as text. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
unsafe_allow_html = truewas the root cause behind both HTML-injection findings from the area 1b review. It was needed only because answers cited sources with<a href>anchors. Citations are now markdown links, and HTML rendering is off.Measured
The answer sweep's 16 questions, run twice each through the real graph:
## Sourcesheading presentThe same four answers are uncited before and after: the off-topic and medical refusals, and the live-data release and species answers. The full sweep passes 16/16.
Changes
[Name](URL).MarkdownLinkStripper: the search page's prose gets labels only, as it did for anchors. It is a streaming stripper that holds back only from a[that could still become a link. Tested at single-character fragments.unsafe_allow_html = false.remark-directive, which reads:p25in "CDK5:p25" as markup and drops it. Anchors had hidden this inside link labels, but prose always had the problem.escape_directivesnow runs on finished answers, and insideescape/inert_html.Verified in a browser
](httpor<a hrefappears as text.🤖 Generated with Claude Code