Skip to content

Escape source and enclosure fields in RSS feed generation - #17209

Merged
matthewp merged 2 commits into
mainfrom
harden-rss-field-escaping
Jun 26, 2026
Merged

matthewp merged 2 commits into
mainfrom
harden-rss-field-escaping

Conversation

@matthewp

Copy link
Copy Markdown
Contributor

Changes

  • Builds the source and enclosure item elements as structured XML objects instead of interpolating values into a string and re-parsing them. This ensures special characters in fields like source.title and enclosure.type are always serialized as text, consistent with how every other feed field is already handled.

Testing

  • Adds two cases covering source and enclosure fields containing XML special characters, asserting the values round-trip verbatim and produce exactly one element each.

Docs

  • No docs update needed; this is an internal serialization change with no API surface change.

@changeset-bot

changeset-bot Bot commented Jun 26, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 7177359

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@astrojs/rss Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@matthewp
matthewp marked this pull request as ready for review June 26, 2026 14:06

@delucis delucis left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

Noting there’s no linked issue in case there was supposed to be one this closes?

@matthewp

Copy link
Copy Markdown
Contributor Author

Yeah, this is something I found outside of an issue.

@matthewp
matthewp merged commit fbcfa03 into main Jun 26, 2026
41 of 42 checks passed
@matthewp
matthewp deleted the harden-rss-field-escaping branch June 26, 2026 14:15
This was referenced Jun 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants