Make inline email images clickable — open full resolution in a new tab

A bare <img> in a rendered email body wasn't wrapped in any link, so the
only way to see it full-size was the browser's right-click "open image in
new tab". sanitizeEmailHtml now wraps every image that isn't already inside
a real link (a sender-linked banner is left alone, no double-wrapping) in
<a href={its own src} target="_blank" rel="noopener noreferrer"> — a normal
left click, middle click, or ctrl-click all now do the expected thing.

The wrapping step (lib/mail/sanitize-html.ts, using the new cheerio dep)
builds the <a> via .attr() rather than string-interpolating the src into an
HTML template — sanitize-html only validates an img src's URL *scheme*, not
that a data: URI's declared content is actually image data, so a crafted
src could otherwise contain characters that break out of an attribute if
naively concatenated into HTML text for re-parsing. Covered by 3 new tests
in sanitize-html.test.ts, including that exact injection attempt.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GteWhnWKTmnXcsd5jx6H7u
This commit is contained in:
ogrechkoandClaude Sonnet 5 committed 2026-08-19 08:43:19 +00:00
1 parent cabcc0b1d4
commit 1a09903326
5 files changed
+254 -5

No files matched your search

+1
View File
@@ -16,6 +16,7 @@
"dependencies": {
"argon2": "^0.45.1",
"better-sqlite3": "^12.11.1",
"cheerio": "^1.2.0",
"drizzle-orm": "^0.45.2",
"framer-motion": "^12.4.7",
"html-to-text": "^10.0.0",