TypeCellOS / TypeCellOS/BlockNote

Off-By-One `RangeError` Crash and Text Duplication in `StyleManager.editLink` and `deleteLink`

Open Beginner friendly
#3,073 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

needs-triage
Dominant language
TypeScript
Stars
10.2k
Forks
772
Avg merge
3d 11h
Merged PRs (30d)
17

Description

What’s broken?

In @blocknote/core, StyleManager.editLink and StyleManager.deleteLink perform an unconditional position + 1 lookup when locating the link mark at the current cursor position:

Inside packages/core/src/editor/managers/StyleManager.ts:220-260:

ts
public editLink(
  url: string,
  text: string,
  position = this.editor.transact((tr) => tr.selection.anchor),
) {
  this.editor.transact((tr) => {
    const linkData = this.getLinkMarkAtPos(position + 1);
    const { from, to } = linkData || {
      from: tr.selection.from,
      to: tr.selection.to,
    };

and in deleteLink:

public deleteLink(
  position = this.editor.transact((tr) => tr.selection.anchor),
) {
  this.editor.transact((tr) => {
    const linkData = this.getLinkMarkAtPos(position + 1);
    const { from, to } = linkData || {
      from: tr.selection.from,
      to: tr.selection.to,
    };
    // 

This causes two major issues:

  1. Unhandled RangeError Crash: If the link is positioned at the very end of the document (position === tr.doc.content.size), position + 1 resolves beyond document bounds. Inside getLinkMarkAtPos, tr.doc.resolve(pos) throws an uncaught RangeError: Position out of range, causing the editor to crash.
  2. Text Duplication & Delete Failure: When the cursor caret is resting at the end of a link (position === link.to), position + 1 queries the character after the link. Since that node lacks the link mark, getLinkMarkAtPos returns undefined and falls back to { from: tr.selection.from, to: tr.selection.to }. Because the selection is a collapsed caret (from === to), editLink inserts the new text beside the old text without replacing it (resulting in OriginalTextEditedText duplication), and deleteLink attempts tr.removeMark(from, to, link) over an empty 0-length range, completely failing to remove the link.
What did you expect to happen?
  1. editLink and deleteLink should never throw an out-of-range error when the cursor is at the end of a document.
  2. When the cursor is positioned at the boundary or end of a link (position === link.to), editLink should successfully replace the existing link text rather than duplicating it, and deleteLink should cleanly remove the link mark.
Steps to reproduce

Scenario A: RangeError Crash

  1. Create a document where a link is the last element: GitHub
  2. Place the cursor at the end of the document (position === editor.prosemirrorState.doc.content.size).
  3. Trigger editor.editLink("https://github.com", "GitHub Homepage") or editor.deleteLink().
  4. Observed: Uncaught RangeError: Position out of range thrown from tr.doc.resolve(pos).

Scenario B: Text Duplication / Failed Deletion

  1. Type a link: Google and place the cursor at the end of the text (position === link.to).
  2. Call editor.editLink("https://google.com", "Google Search").
  3. Observed: The text becomes GoogleGoogle Search instead of Google Search.
  4. Call editor.deleteLink() with the cursor at the same position.
  5. Observed: The link remains active and is not deleted.
BlockNote version

Version: 0.54.0 (and main branch) Package: @blocknote/core

Environment

OS: Any (Windows / macOS / Linux) Browsers: Chrome, Firefox, Safari, Edge Frameworks: Vanilla JS, React, Vue

Additional context

Root Cause

getLinkMarkAtPos expects a valid in-bounds position. Unconditionally adding + 1 breaks on right-boundary cursor positions and document ends.

Proposed Fix

  1. Guard getLinkMarkAtPos against positions exceeding tr.doc.content.size.
  2. Inspect position directly, falling back to position - 1 if the cursor is at the trailing boundary of the link:
--- a/packages/core/src/editor/managers/StyleManager.ts
+++ b/packages/core/src/editor/managers/StyleManager.ts
@@ -154,6 +154,10 @@ export class StyleManager {
     return this.editor.transact((tr) => {
+      const clampedPos = Math.min(Math.max(0, pos), tr.doc.content.size);
+      const resolvedPos = tr.doc.resolve(clampedPos);
       const linkMark = resolvedPos
         .marks()
         .find((mark) => mark.type.name === "link");
@@ -224,7 +228,8 @@ export class StyleManager {
     this.editor.transact((tr) => {
-      const linkData = this.getLinkMarkAtPos(position + 1);
+      const linkData =
+        this.getLinkMarkAtPos(position) ||
+        (position > 0 ? this.getLinkMarkAtPos(position - 1) : undefined);
       const { from, to } = linkData || {
         from: tr.selection.from,
         to: tr.selection.to,
       };
@@ -248,7 +253,8 @@ export class StyleManager {
     this.editor.transact((tr) => {
-      const linkData = this.getLinkMarkAtPos(position + 1);
+      const linkData =
+        this.getLinkMarkAtPos(position) ||
+        (position > 0 ? this.getLinkMarkAtPos(position - 1) : undefined);
       const { from, to } = linkData || {
         from: tr.selection.from,
         to: tr.selection.to,
Contribution
  • I'd be interested in contributing a fix for this issue
Sponsor
  • I'm a sponsor and would appreciate if you could look into this sooner than later 💖

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in packages/core/src/editor/managers/StyleManager.ts, focusing on getLinkMarkAtPos, editLink, and deleteLink around the referenced lines. Reproduce both end-of-document and trailing-link cases, then verify that boundary positions do not throw, editing replaces the link text without duplication, and deletion removes the link mark.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
frontend
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Clearly specified
Newbie friendliness
78/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.