Skip to content

Remove image shorthand syntax {{image}} support - #20

Merged
codeling merged 1 commit into
mainfrom
claude/elegant-albattani-jk27t5
Oct 3, 2026
Merged

codeling merged 1 commit into
mainfrom
claude/elegant-albattani-jk27t5

Conversation

@codeling

@codeling codeling commented Oct 3, 2026

Copy link
Copy Markdown
Owner

This PR removes support for the wiki-specific image shorthand syntax {{image.jpg}} in favor of standard Markdown image syntax ![Alt text](/path/to/image.jpg).

Summary

The custom image shorthand syntax has been completely removed from the codebase. This simplifies the markdown parser and reduces the attack surface for XSS vulnerabilities while maintaining full image support through standard Markdown syntax.

Key Changes

  • Removed image shorthand regex pattern from functions.php that processed {{...}} syntax
  • Updated documentation in MarkdownSyntax.md to remove references to the {{image.png}} shorthand syntax
  • Removed UI hint from index.php drawer that suggested using {{image.jpg}} syntax
  • Removed test cases for image shorthand functionality:
    • Deleted testImageShorthand() from MarkdownToHtmlTest.php
    • Deleted testImageShorthandEscapesFileName() from XssTest.php
    • Removed malicious markdown test cases for image shorthand injection attacks from MaliciousMarkdown.php
  • Updated README.md to remove mention of the shorthand syntax

Implementation Details

  • Users should now use standard Markdown image syntax: ![Alt text](/images/image.jpg) or ![Alt text](/images/image.jpg "Optional title")
  • This change improves security by eliminating a custom parsing rule that was vulnerable to attribute injection attacks
  • The removal is backward-incompatible but aligns the wiki with standard Markdown conventions

https://claude.ai/code/session_01AGfoFJAbyWfHRBNRxyhQCs

…e forms on rename/delete

- resizeImage() returns true on success and throws on failure: report accordingly
- remove the {{name}} shorthand (use ![alt](/images/name))
- rename/delete now also handle titled references and BASE_URI-prefixed paths
- 'Used on page' detection recognizes BASE_URI-prefixed and titled references

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AGfoFJAbyWfHRBNRxyhQCs
@codeling
codeling merged commit 1df21c4 into main Oct 3, 2026
15 checks passed
@codeling
codeling deleted the claude/elegant-albattani-jk27t5 branch October 3, 2026 18:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants