diff --git a/app/lib/formatter.rb b/app/lib/formatter.rb index 12b030e11..0f2989a81 100644 --- a/app/lib/formatter.rb +++ b/app/lib/formatter.rb @@ -92,6 +92,8 @@ class Formatter rel: 'nofollow noopener', } Twitter::Autolink.send(:link_to_text, entity, link_html(entity[:url]), normalized_url, html_attrs) + rescue Addressable::URI::InvalidURIError + encode(entity[:url]) end def link_to_mention(entity, mentions) diff --git a/spec/lib/formatter_spec.rb b/spec/lib/formatter_spec.rb index 81eaf00e8..791bcce86 100644 --- a/spec/lib/formatter_spec.rb +++ b/spec/lib/formatter_spec.rb @@ -123,6 +123,13 @@ RSpec.describe Formatter do expect(subject).to match '

<img src="javascript:alert('XSS');">

' end end + + context 'contains invalid URL' do + let(:local_text) { 'http://www\.google\.com' } + it 'has valid url' do + expect(subject).to eq '

http://www\.google\.com

' + end + end end describe '#reformat' do