Skip to content

[stable34] fix(files): don't expose WebDAV XML-attribute artifacts as DOM attributes - #3290

Open
backportbot[bot] wants to merge 1 commit into
stable34from
backport/3225/stable34
Open

[stable34] fix(files): don't expose WebDAV XML-attribute artifacts as DOM attributes#3290
backportbot[bot] wants to merge 1 commit into
stable34from
backport/3225/stable34

Conversation

@backportbot

@backportbot backportbot Bot commented Jul 20, 2026

Copy link
Copy Markdown

…utes

genFileInfo() flattens every DAV property and runs camelcase() on each
key. Since Nextcloud 33, a file's nc:system-tags property contains
<nc:system-tag> elements that carry XML attributes (can-assign, id,
user-visible, ...). The WebDAV parser represents those attributes with a
leading "@", and camelcase() preserves it, so genFileInfo produced keys
such as "@canAssign". When the resulting object is bound via v-bind in
Viewer.vue, Vue calls setAttribute("@canAssign", ...), which throws
"InvalidCharacterError: Invalid qualified name" on Firefox and Safari
(Chrome silently ignores it). The result is that tagged office files
cannot be opened in those browsers.

Skip the structured system-tags subtree (it is not scalar file metadata)
and, as a defensive backstop, drop any camelCased key that still starts
with "@", so XML-attribute artifacts never reach the DOM.

Ref: nextcloud/richdocuments#5490

Assisted-by: ClaudeCode:Opus-4.8
Signed-off-by: Christoph Schaefer <christoph.schaefer@nextcloud.com>
@backportbot
backportbot Bot requested review from chrip and skjnldsv July 20, 2026 15:17
@backportbot backportbot Bot added bug Something isn't working 3. to review Waiting for reviews feedback-requested labels Jul 20, 2026
@backportbot backportbot Bot added this to the Nextcloud 34.0.2 milestone Jul 20, 2026

@chrip chrip left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Assessment

  • Source: trusted — app/backportbot (is_bot: true), original PR by @chrip, merged 2026-07-20
  • Code: single-file, 22 additions / 4 deletions in src/utils/fileUtils.ts. Skips system-tags DAV property subtree and defensively drops any camelCased key starting with @. Fixes Firefox/Safari crash when opening tagged office files (richdocuments#5490). Logic is correct, matches master PR #3225 verbatim.
  • CI — NPM build FAILURE: the source builds fine (built in 13.96s), but committed JS assets on stable34 don't match the fresh build (chunk hashes differ, some chunks deleted/renamed). This is a pre-existing stable34 asset mismatch, not caused by this PR. The node job is a dummy if true; then exit 1; fi step — irrelevant. All other checks (ESLint, PHP lint, Playwright, Psalm, DCO, REUSE) pass green.
  • CI — "Block merges during freezes" FAILURE: release freeze guard. Separate concern; check with release management if/when to merge.
  • Breaking changes: n/a — this is a bugfix backport, not a dependency bump.
  • Supply chain: n/a — no dependency changes.

Recommended action

The code is correct and all substantive CI checks pass. The NPM build failure is a pre-existing asset-sync issue on stable34 — the fix would be to rebuild and commit the JS assets on the stable34 branch (not something to do on this bot branch). Ask @backportbot or rebase if the branch is updated. Merge once the freeze is lifted and the asset mismatch is resolved on stable34.

Assisted-by: OpenCode:qwen3.6-27b

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews bug Something isn't working feedback-requested

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant