Skip to content
View in the app

A better way to browse. Learn more.

ernestdefoe.online

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.
ernestdefoe.online

Extensions, themes & support for Flarum and Invision Community

Vibe coding for the community web. Report a bug, request a feature, or dig into the source — this is where the tools you use get built, in the open.

We do custom Bespoke Invision Community apps. If you have an idea for something you want then use the contact form to get in touch with us.
Knowledge base

Things that cost me a day, so they cost you none

Working notes from building Invision Community and Flarum applications. Mostly the failures that give no error at all — the ones where everything installs cleanly and quietly does the wrong thing.

92 articles

Invision Community 5

86 articles

Extensions and contracts

39

What each extension point is for, what it must declare, and what happens when it is wrong — which is usually nothing visible.

Languages and text

5

The string table, translation, and the places where text does not appear where you expected it to.

Theming, templates and forms

9

Theme hooks, CSS that survives both colour schemes, and building forms that do not throw on render.

Background work and scheduled tasks

5

The queue system, work that has to happen after the response, and jobs that finish without doing anything.

Data, settings and storage

11

The database layer, settings, tags, file storage, and backing up a live site.

AI features and expectations

5

What these features do, what they cost, and what buyers reasonably but wrongly assume they do.

Application structure and releases

11

The JSON files an application is made of, versioning and upgrade steps, and testing from the command line.

Realtime, chat and calls

1

WebSocket gateways, relays and the server-side pieces live features depend on — where "it works when I test it" and "it works for your members" are different claims.

Nothing matches that.

Why your AI assistant's links arrive as plain text

An assistant that retrieves the right knowledge base article and then cannot give the reader a link to it has lost most of its value. This is a common and slightly embarrassing bug, and it comes from doing exactly the right thing about security in the wrong order.

What it looks like

A customer's report, near enough verbatim:

I wasn't able to get the bot to include an active link to the knowledge base entry in its response. At first, it created the link in Markdown, but after I disabled that option in the settings, it only created it as plain text.

Both halves are the same bug. The reply is being escaped wholesale, so [Title](https://example.com/kb/1) arrives as those literal characters. Turning an editor Markdown option on or off changes nothing, because the content never contained markup to begin with.

The cause

Model output is untrusted text, so it gets escaped before being posted — correctly:

$escaped = htmlspecialchars( $para, ENT_QUOTES | ENT_DISALLOWED, 'UTF-8', false );
$out    .= '<p>' . nl2br( $escaped ) . '</p>';

Invision Community post content is HTML. Escaped text is therefore displayed text, and there is no step that ever turns a URL into an anchor.

The fix, and the order that matters

Convert links after escaping, never before. The input to the converter is already-safe HTML, and it only ever inserts a tag it built itself from a URL it has checked:

/* Markdown links: the brackets survive htmlspecialchars untouched. */
$html = preg_replace_callback(
    '#\[([^\]\n]{1,200})\]\((https?://[^\s()<>"]{1,2000})\)#i',
    fn( $m ) => static::anchor( $m[2], $m[1] ),
    $html
);

/* Then bare URLs, but not ones already inside an href. */
$html = preg_replace_callback(
    '#(?<!href=")(?<!">)\bhttps?://[^\s<>"\']{1,2000}#i',
    function( $m ) {
        /* trailing punctuation belongs to the sentence, not the URL */
        $url  = rtrim( $m[0], '.,;:!?)' );
        $tail = substr( $m[0], strlen( $url ) );
        return static::anchor( $url, $url ) . $tail;
    },
    $html
);
protected static function anchor( string $url, string $label ): string
{
    /* http and https only. A member can talk a model into writing
       javascript: or data:, and this output is posted under an
       official-looking account. */
    if ( !preg_match( '#^https?://#i', html_entity_decode( $url, ENT_QUOTES, 'UTF-8' ) ) )
    {
        return $label;
    }

    return '<a href="' . $url . '" rel="noopener">' . $label . '</a>';
}

Doing it the other way round — linkifying raw model output and escaping afterwards — either destroys the anchors you just built or, far worse, lets the model emit its own markup into a post.

Test the cases that matter

The scheme check is the one to prove, not assume:

'See [the guide](https://example.com/kb/1).'   -> a real link
'It is at https://example.com/kb/1 and works' -> a real link
'Read https://example.com/kb/1.'              -> link, full stop outside it
'Click [here](javascript:alert(1)) now.'      -> NOT a link, left as text
'Try <script>alert(1)</script> and [x](https://a.co)' -> script still escaped
'[Search](https://a.co/x?a=1&b=2)'            -> href keeps &amp;

The & case is worth checking explicitly: because escaping ran first, the ampersand in the query string is already &amp;, which is exactly what an HTML attribute should contain.



User Feedback

Recommended Comments

There are no comments to display.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.