[stable33] fix(files): don't expose WebDAV XML-attribute artifacts as DOM attributes - #3289
Open
backportbot[bot] wants to merge 1 commit into
Open
[stable33] fix(files): don't expose WebDAV XML-attribute artifacts as DOM attributes#3289backportbot[bot] wants to merge 1 commit into
backportbot[bot] wants to merge 1 commit into
Conversation
…utes
genFileInfo() flattens every DAV property and runs camelcase() on each
key. Since Nextcloud 33, a file's nc:system-tags property contains
<nc:system-tag> elements that carry XML attributes (can-assign, id,
user-visible, ...). The WebDAV parser represents those attributes with a
leading "@", and camelcase() preserves it, so genFileInfo produced keys
such as "@canAssign". When the resulting object is bound via v-bind in
Viewer.vue, Vue calls setAttribute("@canAssign", ...), which throws
"InvalidCharacterError: Invalid qualified name" on Firefox and Safari
(Chrome silently ignores it). The result is that tagged office files
cannot be opened in those browsers.
Skip the structured system-tags subtree (it is not scalar file metadata)
and, as a defensive backstop, drop any camelCased key that still starts
with "@", so XML-attribute artifacts never reach the DOM.
Ref: nextcloud/richdocuments#5490
Assisted-by: ClaudeCode:Opus-4.8
Signed-off-by: Christoph Schaefer <christoph.schaefer@nextcloud.com>
chrip
approved these changes
Aug 10, 2026
chrip
left a comment
Contributor
There was a problem hiding this comment.
Assessment
- Source: trusted —
app/backportbot(is_bot: true), original PR by @chrip, merged 2026-07-20 - Code: single-file, 22 additions / 4 deletions in
src/utils/fileUtils.ts. Skipssystem-tagsDAV property subtree and defensively drops any camelCased key starting with@. Fixes Firefox/Safari crash when opening tagged office files (richdocuments#5490). Logic is correct, matches master PR #3225 verbatim. - CI — Psalm FAILURE: pre-existing on stable33.
nextcloud/ocp dev-masterrequires PHP 8.3+, but stable33 composer config has platform PHP set to 8.1.17. Not caused by this PR. - CI — NPM build FAILURE: source builds fine (
built in 14.10s), but committed JS assets on stable34 don't match the fresh build (chunk hashes differ, some chunks deleted/renamed). Pre-existing stable33 asset mismatch, not caused by this PR. Thenodejob is a dummyif true; then exit 1; fistep — irrelevant. - CI — Cypress FAILURE: all 7 runners, 7/7 tests failing. Every failure is "Timed out retrying… Expected to find element" — the test harness can't locate files or viewer elements. Pre-existing test infrastructure issue on stable33, unrelated to this code change.
- CI — "Block merges during freezes" FAILURE: release freeze guard. Separate concern.
- Lint, ESLint, PHP lint, PHP-CS, stylelint, REUSE, DCO: all green.
- Breaking changes: n/a — this is a bugfix backport.
- Supply chain: n/a — no dependency changes.
Recommended action
The code is correct and all non-infrastructural checks pass green. Every red check is a pre-existing issue on stable33:
- Psalm: PHP version mismatch in composer config (stable33 targets PHP 8.1, OCP dev-master requires 8.3+)
- NPM build: stale committed assets — needs a separate PR to rebuild and commit JS artifacts on stable33
- Cypress: test harness can't find elements — environment issue, not related to this fix
Merge once the freeze is lifted. The asset mismatch and Cypress failures on stable33 should be addressed in separate PRs or as part of branch maintenance.
Assisted-by: OpenCode:qwen3.6-27b
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Backport of #3225
Learn more about backports at https://docs.nextcloud.com/server/stable/go.php?to=developer-backports.