Skip to content

[stable33] fix(files): don't expose WebDAV XML-attribute artifacts as DOM attributes - #3289

Open
backportbot[bot] wants to merge 1 commit into
stable33from
backport/3225/stable33
Open

[stable33] fix(files): don't expose WebDAV XML-attribute artifacts as DOM attributes#3289
backportbot[bot] wants to merge 1 commit into
stable33from
backport/3225/stable33

Conversation

@backportbot

@backportbot backportbot Bot commented Jul 20, 2026

Copy link
Copy Markdown

…utes

genFileInfo() flattens every DAV property and runs camelcase() on each
key. Since Nextcloud 33, a file's nc:system-tags property contains
<nc:system-tag> elements that carry XML attributes (can-assign, id,
user-visible, ...). The WebDAV parser represents those attributes with a
leading "@", and camelcase() preserves it, so genFileInfo produced keys
such as "@canAssign". When the resulting object is bound via v-bind in
Viewer.vue, Vue calls setAttribute("@canAssign", ...), which throws
"InvalidCharacterError: Invalid qualified name" on Firefox and Safari
(Chrome silently ignores it). The result is that tagged office files
cannot be opened in those browsers.

Skip the structured system-tags subtree (it is not scalar file metadata)
and, as a defensive backstop, drop any camelCased key that still starts
with "@", so XML-attribute artifacts never reach the DOM.

Ref: nextcloud/richdocuments#5490

Assisted-by: ClaudeCode:Opus-4.8
Signed-off-by: Christoph Schaefer <christoph.schaefer@nextcloud.com>
@backportbot
backportbot Bot requested review from chrip and skjnldsv July 20, 2026 15:17
@backportbot backportbot Bot added bug Something isn't working 3. to review Waiting for reviews feedback-requested labels Jul 20, 2026
@backportbot backportbot Bot added this to the Nextcloud 33.0.7 milestone Jul 20, 2026

@chrip chrip left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Assessment

  • Source: trusted — app/backportbot (is_bot: true), original PR by @chrip, merged 2026-07-20
  • Code: single-file, 22 additions / 4 deletions in src/utils/fileUtils.ts. Skips system-tags DAV property subtree and defensively drops any camelCased key starting with @. Fixes Firefox/Safari crash when opening tagged office files (richdocuments#5490). Logic is correct, matches master PR #3225 verbatim.
  • CI — Psalm FAILURE: pre-existing on stable33. nextcloud/ocp dev-master requires PHP 8.3+, but stable33 composer config has platform PHP set to 8.1.17. Not caused by this PR.
  • CI — NPM build FAILURE: source builds fine (built in 14.10s), but committed JS assets on stable34 don't match the fresh build (chunk hashes differ, some chunks deleted/renamed). Pre-existing stable33 asset mismatch, not caused by this PR. The node job is a dummy if true; then exit 1; fi step — irrelevant.
  • CI — Cypress FAILURE: all 7 runners, 7/7 tests failing. Every failure is "Timed out retrying… Expected to find element" — the test harness can't locate files or viewer elements. Pre-existing test infrastructure issue on stable33, unrelated to this code change.
  • CI — "Block merges during freezes" FAILURE: release freeze guard. Separate concern.
  • Lint, ESLint, PHP lint, PHP-CS, stylelint, REUSE, DCO: all green.
  • Breaking changes: n/a — this is a bugfix backport.
  • Supply chain: n/a — no dependency changes.

Recommended action

The code is correct and all non-infrastructural checks pass green. Every red check is a pre-existing issue on stable33:

  1. Psalm: PHP version mismatch in composer config (stable33 targets PHP 8.1, OCP dev-master requires 8.3+)
  2. NPM build: stale committed assets — needs a separate PR to rebuild and commit JS artifacts on stable33
  3. Cypress: test harness can't find elements — environment issue, not related to this fix

Merge once the freeze is lifted. The asset mismatch and Cypress failures on stable33 should be addressed in separate PRs or as part of branch maintenance.

Assisted-by: OpenCode:qwen3.6-27b

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews bug Something isn't working feedback-requested

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant