From 60e1bd52f71131f84d2e9662e1ebef2b1a696f4a Mon Sep 17 00:00:00 2001 From: Devvyn <22340871+opticon454@users.noreply.github.com> Date: Wed, 16 Sep 2026 07:00:55 +0800 Subject: [PATCH] =?UTF-8?q?fix(custom-model):=20act=20on=20the=20draft=20r?= =?UTF-8?q?eview=20=E2=80=94=20unparseable=20onclick,=20unwrapped=20envelo?= =?UTF-8?q?pe,=20wrong-session=20apply,=20missing=20lock,=20no=20tests?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Addresses every blocker, both majors, and all but one minor from the maintainer's review of the draft PR. Blockers: 1. Every generated inline onclick was unparseable. JSON.stringify's own double quotes terminated the double-quoted HTML attribute at the first one, leaving btn.onclick null on every picker entry and every Discover/ Edit/Delete button. Fixed with escapeHtml(JSON.stringify(...)) per argument, the same idiom deleteCase's onclick already uses four lines away in session-ui.js. This also closes the live-HTML-injection route through modelId (server-controlled, from the endpoint's own /v1/models reply): with quoting intact, a `>` inside it can no longer terminate the @@ -2216,42 +2216,46 @@ Enable custom model endpoints Adds a per-endpoint entry to the Run menu for every harness that can redirect to one. - + -
- -