Skip to content

Fix CodeTailor Parsons blocks mangling comparison operators - #1445

Open
aspadiyath wants to merge 1 commit into
RunestoneInteractive:mainfrom
aspadiyath:fix-codetailor-parsons-operator-mangling
Open

Fix CodeTailor Parsons blocks mangling comparison operators#1445
aspadiyath wants to merge 1 commit into
RunestoneInteractive:mainfrom
aspadiyath:fix-codetailor-parsons-operator-mangling

Conversation

@aspadiyath

Copy link
Copy Markdown
Contributor

Before embedding the generated "---"-separated block markup into a

 element, coach.py ran
re.sub(r"<(?=\S)", "< ", block) to keep a bare "<" in the code from being misread as an HTML tag when parsons.js re-parses the element's innerHTML. That regex fired on every "<" followed by a non-space, so Python comparison operators were corrupted in the puzzle: "hours <= 1" rendered (and got dragged into the assembled solution) as "hours < = 1", and the code no longer ran.

Escape "<" to "<" instead. The Parsons widget already renders escaped entities back to their literal characters (that's how DB-authored markup survives extract_parsons_code), so the blocks now show "<=" correctly with no tag-injection risk. Only "<" is escaped, matching the original scope -- bare "&"/">" were never touched and render fine inside

.

The clipboard "copy answer" path is unaffected: it uses the separate first ||split|| segment (the plain code solution), not the escaped block markup.

Before embedding the generated "---"-separated block markup into a
<pre class="parsonsblocks"> element, coach.py ran
re.sub(r"<(?=\S)", "< ", block) to keep a bare "<" in the code from
being misread as an HTML tag when parsons.js re-parses the element's
innerHTML. That regex fired on every "<" followed by a non-space, so
Python comparison operators were corrupted in the puzzle: "hours <= 1"
rendered (and got dragged into the assembled solution) as "hours < = 1",
and the code no longer ran.

Escape "<" to "&lt;" instead. The Parsons widget already renders escaped
entities back to their literal characters (that's how DB-authored markup
survives extract_parsons_code), so the blocks now show "<=" correctly
with no tag-injection risk. Only "<" is escaped, matching the original
scope -- bare "&"/">" were never touched and render fine inside <pre>.

The clipboard "copy answer" path is unaffected: it uses the separate
first ||split|| segment (the plain code solution), not the escaped block
markup.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@aspadiyath
aspadiyath requested a review from bnmnetp as a code owner August 28, 2026 16:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant