Repository navigation
fix(leads): a link ends where its URL characters end - #156
Merged
Merged
Conversation
The live draft read "...at https://threatcrush.com/get-whitepaper—download takes a minute", and the guard extracted the URL as "https://threatcrush.com/get-whitepaper—download" — matched it against the campaign, found nothing, and rejected the draft for linking somewhere invented. The campaign had declared that URL. The em-dash was prose. Matching "anything up to whitespace" is what did it. Non-ASCII cannot appear in a URL without being percent-encoded, so the dash was never part of the link; the pattern now matches only what RFC 3986 permits, and trailing sentence punctuation is stripped rather than only a full stop or a comma. The draft is also repaired rather than merely re-checked. A URL welded to an em-dash is one some mail clients will autolink including the dash, which is a 404 on the single thing the email asked the recipient to click — so a space is inserted, and the tidied body is what gets sent. Checking a repaired draft and then sending the broken original would have been worse than not repairing it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
vu1nz Security Review0 finding(s) in PR #? No security issues found. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
From the production run log, 15:46:
The campaign had declared that URL:
The draft read "…at https://threatcrush.com/get-whitepaper—download takes a minute". The em-dash was prose. The guard's pattern —
[^\s)>\]]+, anything up to whitespace — swallowed it and the word after it, then rejected the draft for linking somewhere invented.The pattern was simply wrong
Non-ASCII can't appear in a URL without percent-encoding, so the dash was never part of the link. Now matching only what RFC 3986 permits, with trailing sentence punctuation stripped rather than just
.and,:The draft is repaired, not just re-checked
A URL welded to an em-dash is one some mail clients autolink including the dash — a 404 on the single thing the email asked the recipient to click. So a space is inserted and the tidied body is what gets sent. Checking a repaired draft and sending the broken original would be worse than not repairing it.
An invented link is still caught — pinned by a test, since that's the guard's job.
Checks
tsc --noEmitclean · 1,049 tests pass (7 new) · build compiles🤖 Generated with Claude Code