• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

IJHack / QtPass / 34835404439
93%

Build:
DEFAULT BRANCH: main
Ran 14 Sep 2026 11:02AM UTC
Jobs 1
Files 88
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

14 Sep 2026 10:53AM UTC coverage: 67.818% (+0.02%) from 67.8%
34835404439

push

github

web-flow
Backport: Only link launchable http(s) URLs in inline anchors (#1709) (#1726)

* Only link launchable http(s) URLs in inline anchors (#1682)

Util::protocolRegex() matches ssh://, sftp://, ftp:// and webdav:// as
well as URLs carrying user:pass@ credentials. PasswordDisplayPanel and
QtPass::showInTextBrowser()/processErrorExit() wrapped every match in
<a href>, and both QTextBrowsers call setOpenExternalLinks(true), so a
click handed a non-web scheme or embedded credentials straight to the
OS URL handler, bypassing Util::isLaunchableWebUrl(), the gate the
open-in-browser button already uses.

Add Util::linkifyUrls(): HTML-escape the text and turn only the
protocolRegex() matches that also pass isLaunchableWebUrl() into
anchors; everything else stays escaped plain text. Use it at all three
anchor-producing sites so detection and gating share one predicate.

Tests: tst_util covers the helper (https anchors, ssh/ftp/creds as
text, mixed content, escaping); tst_passworddisplaypanel checks that
ssh://user:pass@host, ftp://host and friends render without an anchor
or URL button while https://example.org/?a=1&b=2 still links.

Backport to 1.8 (main): PasswordDisplayPanel on main still renders every
field value through QTextBrowser::setText(), so the setPlainText()/setHtml()
split from #1683 is not present; the panel simply hands the value to
Util::linkifyUrls() and keeps setText(). The panel test file on main lacks
the browserAt()/urlButtonAt() helpers and the #1683/#1693 tests, so only
the two #1719 tests and the two helpers they need were carried over.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JuQsrHonihp1nARE7bzstc
(cherry picked from commit e8cd63d06)

* Address review: stop protocolRegex at any whitespace

The URL delimiter in Util::protocolRegex() excluded only a literal
space, so on the two multi-line call sites of Util::linkifyUrls()
(QtPass::showInTextBrowse... (continued)

27 of 27 new or added lines in 3 files covered. (100.0%)

4948 of 7296 relevant lines covered (67.82%)

66.57 hits per line

Jobs
ID Job ID Ran Files Coverage
1 34835404439.1 14 Sep 2026 11:02AM UTC 88
67.82
GitHub Action Run
Source Files on build 34835404439
  • Tree
  • List 88
  • Changed 5
  • Source Changed 5
  • Coverage Changed 3
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #34835404439
  • 5a321366 on github
  • Prev Build on main (#34834943654)
  • Next Build on main (#34835706449)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc