TypeCellOS / TypeCellOS/BlockNote
Off-By-One `RangeError` Crash and Text Duplication in `StyleManager.editLink` and `deleteLink`
Personne n'a encore pris cette issue.
- Langage dominant
- TypeScript
- Étoiles
- 10.2k
- Forks
- 772
- Merge moyen
- 3 j 11 h
- PR mergées (30 j)
- 17
Description
What’s broken?
In @blocknote/core, StyleManager.editLink and StyleManager.deleteLink perform an unconditional position + 1 lookup when locating the link mark at the current cursor position:
Inside packages/core/src/editor/managers/StyleManager.ts:220-260:
ts
public editLink(
url: string,
text: string,
position = this.editor.transact((tr) => tr.selection.anchor),
) {
this.editor.transact((tr) => {
const linkData = this.getLinkMarkAtPos(position + 1);
const { from, to } = linkData || {
from: tr.selection.from,
to: tr.selection.to,
};
and in deleteLink:
public deleteLink(
position = this.editor.transact((tr) => tr.selection.anchor),
) {
this.editor.transact((tr) => {
const linkData = this.getLinkMarkAtPos(position + 1);
const { from, to } = linkData || {
from: tr.selection.from,
to: tr.selection.to,
};
//
This causes two major issues:
- Unhandled RangeError Crash: If the link is positioned at the very end of the document (position === tr.doc.content.size), position + 1 resolves beyond document bounds. Inside getLinkMarkAtPos, tr.doc.resolve(pos) throws an uncaught RangeError: Position out of range, causing the editor to crash.
- Text Duplication & Delete Failure: When the cursor caret is resting at the end of a link (position === link.to), position + 1 queries the character after the link. Since that node lacks the link mark, getLinkMarkAtPos returns undefined and falls back to { from: tr.selection.from, to: tr.selection.to }. Because the selection is a collapsed caret (from === to), editLink inserts the new text beside the old text without replacing it (resulting in OriginalTextEditedText duplication), and deleteLink attempts tr.removeMark(from, to, link) over an empty 0-length range, completely failing to remove the link.
What did you expect to happen?
- editLink and deleteLink should never throw an out-of-range error when the cursor is at the end of a document.
- When the cursor is positioned at the boundary or end of a link (position === link.to), editLink should successfully replace the existing link text rather than duplicating it, and deleteLink should cleanly remove the link mark.
Steps to reproduce
Scenario A: RangeError Crash
- Create a document where a link is the last element: GitHub
- Place the cursor at the end of the document (position === editor.prosemirrorState.doc.content.size).
- Trigger editor.editLink("https://github.com", "GitHub Homepage") or editor.deleteLink().
- Observed: Uncaught RangeError: Position out of range thrown from tr.doc.resolve(pos).
Scenario B: Text Duplication / Failed Deletion
- Type a link: Google and place the cursor at the end of the text (position === link.to).
- Call editor.editLink("https://google.com", "Google Search").
- Observed: The text becomes GoogleGoogle Search instead of Google Search.
- Call editor.deleteLink() with the cursor at the same position.
- Observed: The link remains active and is not deleted.
BlockNote version
Version: 0.54.0 (and main branch) Package: @blocknote/core
Environment
OS: Any (Windows / macOS / Linux) Browsers: Chrome, Firefox, Safari, Edge Frameworks: Vanilla JS, React, Vue
Additional context
Root Cause
getLinkMarkAtPos expects a valid in-bounds position. Unconditionally adding + 1 breaks on right-boundary cursor positions and document ends.
Proposed Fix
- Guard getLinkMarkAtPos against positions exceeding tr.doc.content.size.
- Inspect position directly, falling back to position - 1 if the cursor is at the trailing boundary of the link:
--- a/packages/core/src/editor/managers/StyleManager.ts
+++ b/packages/core/src/editor/managers/StyleManager.ts
@@ -154,6 +154,10 @@ export class StyleManager {
return this.editor.transact((tr) => {
+ const clampedPos = Math.min(Math.max(0, pos), tr.doc.content.size);
+ const resolvedPos = tr.doc.resolve(clampedPos);
const linkMark = resolvedPos
.marks()
.find((mark) => mark.type.name === "link");
@@ -224,7 +228,8 @@ export class StyleManager {
this.editor.transact((tr) => {
- const linkData = this.getLinkMarkAtPos(position + 1);
+ const linkData =
+ this.getLinkMarkAtPos(position) ||
+ (position > 0 ? this.getLinkMarkAtPos(position - 1) : undefined);
const { from, to } = linkData || {
from: tr.selection.from,
to: tr.selection.to,
};
@@ -248,7 +253,8 @@ export class StyleManager {
this.editor.transact((tr) => {
- const linkData = this.getLinkMarkAtPos(position + 1);
+ const linkData =
+ this.getLinkMarkAtPos(position) ||
+ (position > 0 ? this.getLinkMarkAtPos(position - 1) : undefined);
const { from, to } = linkData || {
from: tr.selection.from,
to: tr.selection.to,
Contribution
- I'd be interested in contributing a fix for this issue
Sponsor
- I'm a sponsor and would appreciate if you could look into this sooner than later 💖
Guide de contribution
Ouvrir le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Piste de recherche
Commencez dans packages/core/src/editor/managers/StyleManager.ts, en vous concentrant sur getLinkMarkAtPos, editLink et deleteLink autour des lignes référencées. Reproduisez à la fois le cas de fin de document et le cas d’un lien final, puis vérifiez que les positions limites ne déclenchent pas d’exception, que la modification remplace le texte du lien sans duplication et que la suppression retire la marque de lien.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- typescript
- Domaine
- frontend
- Type d'issue
- Bug
- Difficulté
- 2/5
- Temps estimé
- 1-3 heures
- Activité
- Active
- Clarté
- Clairement spécifiée
- Accessibilité débutants
- 78/100