Off-By-One `RangeError` Crash and Text Duplication in `StyleManager.editLink` and `deleteLink`

オープン 初心者向け
#3,073 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
78/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
typescript
領域
frontend

調査の方向性

packages/core/src/editor/managers/StyleManager.ts から始め、参照されている行付近の getLinkMarkAtPos、editLink、deleteLink に注目してください。ドキュメント末尾の場合と末尾にリンクがある場合の両方を再現し、そのうえで境界位置で例外が発生しないこと、編集によってリンクテキストが重複せずに置き換えられること、削除によってリンクマークが取り除かれることを確認してください。

索引モデルが issue の本文から書いたものです。

説明

needs-triage
What’s broken?

In @blocknote/core, StyleManager.editLink and StyleManager.deleteLink perform an unconditional position + 1 lookup when locating the link mark at the current cursor position:

Inside packages/core/src/editor/managers/StyleManager.ts:220-260:

ts
public editLink(
  url: string,
  text: string,
  position = this.editor.transact((tr) => tr.selection.anchor),
) {
  this.editor.transact((tr) => {
    const linkData = this.getLinkMarkAtPos(position + 1);
    const { from, to } = linkData || {
      from: tr.selection.from,
      to: tr.selection.to,
    };

and in deleteLink:

public deleteLink(
  position = this.editor.transact((tr) => tr.selection.anchor),
) {
  this.editor.transact((tr) => {
    const linkData = this.getLinkMarkAtPos(position + 1);
    const { from, to } = linkData || {
      from: tr.selection.from,
      to: tr.selection.to,
    };
    // 

This causes two major issues:

  1. Unhandled RangeError Crash: If the link is positioned at the very end of the document (position === tr.doc.content.size), position + 1 resolves beyond document bounds. Inside getLinkMarkAtPos, tr.doc.resolve(pos) throws an uncaught RangeError: Position out of range, causing the editor to crash.
  2. Text Duplication & Delete Failure: When the cursor caret is resting at the end of a link (position === link.to), position + 1 queries the character after the link. Since that node lacks the link mark, getLinkMarkAtPos returns undefined and falls back to { from: tr.selection.from, to: tr.selection.to }. Because the selection is a collapsed caret (from === to), editLink inserts the new text beside the old text without replacing it (resulting in OriginalTextEditedText duplication), and deleteLink attempts tr.removeMark(from, to, link) over an empty 0-length range, completely failing to remove the link.
What did you expect to happen?
  1. editLink and deleteLink should never throw an out-of-range error when the cursor is at the end of a document.
  2. When the cursor is positioned at the boundary or end of a link (position === link.to), editLink should successfully replace the existing link text rather than duplicating it, and deleteLink should cleanly remove the link mark.
Steps to reproduce

Scenario A: RangeError Crash

  1. Create a document where a link is the last element: GitHub
  2. Place the cursor at the end of the document (position === editor.prosemirrorState.doc.content.size).
  3. Trigger editor.editLink("https://github.com", "GitHub Homepage") or editor.deleteLink().
  4. Observed: Uncaught RangeError: Position out of range thrown from tr.doc.resolve(pos).

Scenario B: Text Duplication / Failed Deletion

  1. Type a link: Google and place the cursor at the end of the text (position === link.to).
  2. Call editor.editLink("https://google.com", "Google Search").
  3. Observed: The text becomes GoogleGoogle Search instead of Google Search.
  4. Call editor.deleteLink() with the cursor at the same position.
  5. Observed: The link remains active and is not deleted.
BlockNote version

Version: 0.54.0 (and main branch) Package: @blocknote/core

Environment

OS: Any (Windows / macOS / Linux) Browsers: Chrome, Firefox, Safari, Edge Frameworks: Vanilla JS, React, Vue

Additional context

Root Cause

getLinkMarkAtPos expects a valid in-bounds position. Unconditionally adding + 1 breaks on right-boundary cursor positions and document ends.

Proposed Fix

  1. Guard getLinkMarkAtPos against positions exceeding tr.doc.content.size.
  2. Inspect position directly, falling back to position - 1 if the cursor is at the trailing boundary of the link:
--- a/packages/core/src/editor/managers/StyleManager.ts
+++ b/packages/core/src/editor/managers/StyleManager.ts
@@ -154,6 +154,10 @@ export class StyleManager {
     return this.editor.transact((tr) => {
+      const clampedPos = Math.min(Math.max(0, pos), tr.doc.content.size);
+      const resolvedPos = tr.doc.resolve(clampedPos);
       const linkMark = resolvedPos
         .marks()
         .find((mark) => mark.type.name === "link");
@@ -224,7 +228,8 @@ export class StyleManager {
     this.editor.transact((tr) => {
-      const linkData = this.getLinkMarkAtPos(position + 1);
+      const linkData =
+        this.getLinkMarkAtPos(position) ||
+        (position > 0 ? this.getLinkMarkAtPos(position - 1) : undefined);
       const { from, to } = linkData || {
         from: tr.selection.from,
         to: tr.selection.to,
       };
@@ -248,7 +253,8 @@ export class StyleManager {
     this.editor.transact((tr) => {
-      const linkData = this.getLinkMarkAtPos(position + 1);
+      const linkData =
+        this.getLinkMarkAtPos(position) ||
+        (position > 0 ? this.getLinkMarkAtPos(position - 1) : undefined);
       const { from, to } = linkData || {
         from: tr.selection.from,
         to: tr.selection.to,
Contribution
  • I'd be interested in contributing a fix for this issue
Sponsor
  • I'm a sponsor and would appreciate if you could look into this sooner than later 💖
主要言語
TypeScript
スター
10.2k
フォーク
772
平均マージ
3日 11時間
マージ済み PR(30日)
17

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

TypeCellOS/BlockNote のほかの issue

TypeCellOS/BlockNote の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。