fix(desktop): refuse backtick in URL artifact capture (#118415)

normalizeValue's trailing trim cannot save a URL captured THROUGH its
closing inline-code backtick when punctuation follows the delimiter
(`https://voice.qwickapps.com`,): the punctuation strip runs first and
leaves the backtick on the stored value/href, so the preview fails.
Exclude the backtick from URL_RE's char class — the capture now stops at
the delimiter itself, matching PATH_RE which already refuses it.

Builds on #118416 (cherry-picked in the previous commit).
This commit is contained in:
Hermes Agent
2026-09-24 18:36:24 -05:00
committed by brooklyn!
parent fdde5ee1ab
commit e3841b1a0e
2 changed files with 21 additions and 1 deletions

View File

@@ -30,7 +30,7 @@ export interface ArtifactLoadResult {
const MARKDOWN_IMAGE_RE = /!\[([^\]]*)\]\(([^)\s]+)\)/g
const MARKDOWN_LINK_RE = /\[([^\]]+)\]\(([^)\s]+)\)/g
const URL_RE = /https?:\/\/[^\s<>"')]+/g
const URL_RE = /https?:\/\/[^\s<>"')`]+/g
const PATH_RE = /(^|[\s("'`])((?:\/|~[\\/]|\.\.?[\\/]|\\\\)[^\s"'`<>]+(?:\.[a-z0-9]{1,8})?)/gi
const WINDOWS_PATH_RE = /(^|[\s("'`])([A-Za-z]:[\\/][^\s"'`<>]+(?:\.[a-z0-9]{1,8})?)/gi
const IMAGE_EXT_RE = /\.(?:png|jpe?g|gif|webp|svg|bmp)(?:\?.*)?$/i

View File

@@ -65,6 +65,26 @@ describe('collectArtifactsForSession', () => {
})
})
it('stops a URL capture at a closing backtick even when punctuation follows it', () => {
// The closing delimiter can carry trailing punctuation (`…`,) — the
// trailing-punctuation trim alone would leave the backtick behind, so the
// capture itself must refuse it.
const artifacts = collectArtifactsForSession(makeSession(), [
{
content: 'Deployed at `https://voice.qwickapps.com`, take a look.',
role: 'assistant',
timestamp: 2000
}
])
expect(artifacts).toHaveLength(1)
expect(artifacts[0]).toMatchObject({
href: 'https://voice.qwickapps.com',
kind: 'link',
value: 'https://voice.qwickapps.com'
})
})
it('does not index passive links and paths observed in tool output', () => {
const messages: SessionMessage[] = [
{