Skip to content

fix: treat col as a self-closing tag - #5447

Merged
BoDonkey merged 2 commits into
apostrophecms:mainfrom
vansh1011:main
Jun 16, 2026
Merged

BoDonkey merged 2 commits into
apostrophecms:mainfrom
vansh1011:main

Conversation

@vansh1011

Copy link
Copy Markdown
Contributor

Summary

Fixes #5443 by adding col to the selfClosing tag list.

<col> is a void HTML element and should not be serialized with a closing tag. Previously, sanitize-html could output invalid HTML by converting a <col> element into <col></col>.

Changes

  • Added col to the default selfClosing tag list.
  • Added a regression test covering this behavior.

Testing

  • Added a test that reproduces the issue.
  • Verified the test passes after the fix.
  • Ran the sanitize-html test suite.

@boutell
boutell requested a review from BoDonkey June 11, 2026 17:20

@BoDonkey BoDonkey left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me. I didn't realize that sanitize added a trailing slash to self-closing tags, so it caused me to look at the test twice.

@BoDonkey
BoDonkey merged commit 6fb990a into apostrophecms:main Jun 16, 2026
BoDonkey pushed a commit that referenced this pull request Jun 18, 2026
* fix: treat col as a self-closing tag
boutell added a commit that referenced this pull request Jul 8, 2026
* Fix asset URLs when a site prefix is configured (#5448)

* fix: treat col as a self-closing tag (#5447)

* fix: treat col as a self-closing tag

* Make dateTime field responsive (css) (#5481)

* Fix/from rich text adds metatype (#5488)

* fromRichText adds metatype to new widget

* change

* nodemailer major bump (#5485)

* Harden and centralize the cache invalidation (#5493)

* fix(sanitize-html): emit transformTags text on empty tags when textFilter is set (#5494)

When a transformTags handler adds text to an allowed tag that originally had
no text content, the injected text was silently dropped if any textFilter was
configured. The onopentag branch that emits frame.innerText was guarded by
!options.textFilter, deferring emission to ontext so the filter could run
there. For an empty element htmlparser2 never fires ontext, so the text was
emitted by neither branch.

Emit frame.innerText through options.textFilter here when present (mirroring
the discard path), so the transformTags text contract holds for empty tags
regardless of whether a textFilter is set.

* changeset crediting spokodev for sanitize-html fix (#5498)

* Fix shortcut conflicts (#5499)

* Fix backspace after slash deleting a rich-text widget

* Fix copy/paste widget/text conflicts

* Fix astro redirects (#5500)

* Merge commit from fork

* Merge commit from fork

* Merge commit from fork

* Merge commit from fork

* fix path traversal in import/export

* correct credits

* additional guards

* Merge commit from fork

* fix for </textarea/> vulnerability (#5501)

* wip

* fix for math/svg vulnerabilities

---------

Co-authored-by: Jinka Manohar <145598597+Manohar2503@users.noreply.github.com>
Co-authored-by: Vansh Parmar <vanshparmar8742@gmail.com>
Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com>
Co-authored-by: Stuart Romanek <stuart@apostrophecms.com>
Co-authored-by: spokodev <spoko.dev@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

sanitize-html: col element is self-closing

2 participants