TypeCellOS / TypeCellOS/BlockNote

Off-By-One `RangeError` Crash and Text Duplication in `StyleManager.editLink` and `deleteLink`

Ouverte Adaptée aux débutants
#3,073 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub

Personne n'a encore pris cette issue.

needs-triage
Langage dominant
TypeScript
Étoiles
10.2k
Forks
772
Merge moyen
3 j 11 h
PR mergées (30 j)
17

Description

What’s broken?

In @blocknote/core, StyleManager.editLink and StyleManager.deleteLink perform an unconditional position + 1 lookup when locating the link mark at the current cursor position:

Inside packages/core/src/editor/managers/StyleManager.ts:220-260:

ts
public editLink(
  url: string,
  text: string,
  position = this.editor.transact((tr) => tr.selection.anchor),
) {
  this.editor.transact((tr) => {
    const linkData = this.getLinkMarkAtPos(position + 1);
    const { from, to } = linkData || {
      from: tr.selection.from,
      to: tr.selection.to,
    };

and in deleteLink:

public deleteLink(
  position = this.editor.transact((tr) => tr.selection.anchor),
) {
  this.editor.transact((tr) => {
    const linkData = this.getLinkMarkAtPos(position + 1);
    const { from, to } = linkData || {
      from: tr.selection.from,
      to: tr.selection.to,
    };
    // 

This causes two major issues:

  1. Unhandled RangeError Crash: If the link is positioned at the very end of the document (position === tr.doc.content.size), position + 1 resolves beyond document bounds. Inside getLinkMarkAtPos, tr.doc.resolve(pos) throws an uncaught RangeError: Position out of range, causing the editor to crash.
  2. Text Duplication & Delete Failure: When the cursor caret is resting at the end of a link (position === link.to), position + 1 queries the character after the link. Since that node lacks the link mark, getLinkMarkAtPos returns undefined and falls back to { from: tr.selection.from, to: tr.selection.to }. Because the selection is a collapsed caret (from === to), editLink inserts the new text beside the old text without replacing it (resulting in OriginalTextEditedText duplication), and deleteLink attempts tr.removeMark(from, to, link) over an empty 0-length range, completely failing to remove the link.
What did you expect to happen?
  1. editLink and deleteLink should never throw an out-of-range error when the cursor is at the end of a document.
  2. When the cursor is positioned at the boundary or end of a link (position === link.to), editLink should successfully replace the existing link text rather than duplicating it, and deleteLink should cleanly remove the link mark.
Steps to reproduce

Scenario A: RangeError Crash

  1. Create a document where a link is the last element: GitHub
  2. Place the cursor at the end of the document (position === editor.prosemirrorState.doc.content.size).
  3. Trigger editor.editLink("https://github.com", "GitHub Homepage") or editor.deleteLink().
  4. Observed: Uncaught RangeError: Position out of range thrown from tr.doc.resolve(pos).

Scenario B: Text Duplication / Failed Deletion

  1. Type a link: Google and place the cursor at the end of the text (position === link.to).
  2. Call editor.editLink("https://google.com", "Google Search").
  3. Observed: The text becomes GoogleGoogle Search instead of Google Search.
  4. Call editor.deleteLink() with the cursor at the same position.
  5. Observed: The link remains active and is not deleted.
BlockNote version

Version: 0.54.0 (and main branch) Package: @blocknote/core

Environment

OS: Any (Windows / macOS / Linux) Browsers: Chrome, Firefox, Safari, Edge Frameworks: Vanilla JS, React, Vue

Additional context

Root Cause

getLinkMarkAtPos expects a valid in-bounds position. Unconditionally adding + 1 breaks on right-boundary cursor positions and document ends.

Proposed Fix

  1. Guard getLinkMarkAtPos against positions exceeding tr.doc.content.size.
  2. Inspect position directly, falling back to position - 1 if the cursor is at the trailing boundary of the link:
--- a/packages/core/src/editor/managers/StyleManager.ts
+++ b/packages/core/src/editor/managers/StyleManager.ts
@@ -154,6 +154,10 @@ export class StyleManager {
     return this.editor.transact((tr) => {
+      const clampedPos = Math.min(Math.max(0, pos), tr.doc.content.size);
+      const resolvedPos = tr.doc.resolve(clampedPos);
       const linkMark = resolvedPos
         .marks()
         .find((mark) => mark.type.name === "link");
@@ -224,7 +228,8 @@ export class StyleManager {
     this.editor.transact((tr) => {
-      const linkData = this.getLinkMarkAtPos(position + 1);
+      const linkData =
+        this.getLinkMarkAtPos(position) ||
+        (position > 0 ? this.getLinkMarkAtPos(position - 1) : undefined);
       const { from, to } = linkData || {
         from: tr.selection.from,
         to: tr.selection.to,
       };
@@ -248,7 +253,8 @@ export class StyleManager {
     this.editor.transact((tr) => {
-      const linkData = this.getLinkMarkAtPos(position + 1);
+      const linkData =
+        this.getLinkMarkAtPos(position) ||
+        (position > 0 ? this.getLinkMarkAtPos(position - 1) : undefined);
       const { from, to } = linkData || {
         from: tr.selection.from,
         to: tr.selection.to,
Contribution
  • I'd be interested in contributing a fix for this issue
Sponsor
  • I'm a sponsor and would appreciate if you could look into this sooner than later 💖

Guide de contribution

Ouvrir le guide de contribution

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Piste de recherche

Commencez dans packages/core/src/editor/managers/StyleManager.ts, en vous concentrant sur getLinkMarkAtPos, editLink et deleteLink autour des lignes référencées. Reproduisez à la fois le cas de fin de document et le cas d’un lien final, puis vérifiez que les positions limites ne déclenchent pas d’exception, que la modification remplace le texte du lien sans duplication et que la suppression retire la marque de lien.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
typescript
Domaine
frontend
Type d'issue
Bug
Difficulté
2/5
Temps estimé
1-3 heures
Activité
Active
Clarté
Clairement spécifiée
Accessibilité débutants
78/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.