Skip to content

fix(markdown): apply disallowedNodes to MDX elements by rule key - #5141

Open
zbeyens wants to merge 2 commits into
mainfrom
codex/5140-mdx-node-filters
Open

zbeyens wants to merge 2 commits into
mainfrom
codex/5140-mdx-node-filters

Conversation

@zbeyens

@zbeyens zbeyens commented Oct 3, 2026 •

Copy link
Copy Markdown
Member
  • Auto release

🧭 Task plan: docs/plans/5140-mdx-element-node-filters.md

Closes #5140

Why

With remark-mdx, deserializeMd checked allowedNodes and disallowedNodes against an inline HTML element's mdast type, mdxJsxTextElement, never against the node its rule produces. disallowedNodes: ['a'] dropped Markdown links but kept <a href> anchors, and since #5139 those anchors keep their URL.

Scope

  • customMdxDeserialize (packages/markdown/src/lib/deserializer/utils/customMdxDeserialize.ts) resolves the element's rule key once: the plugin key the tag resolves to, or the tag name when no plugin owns it. When a rule exists and disallowedNodes lists that key, it returns nothing before the rule runs. a removes <a href>, underline removes <u>, br removes <br>.
  • allowedNodes and allowNode keep their behavior. The allowedNodes and disallowedNodes JSDoc in MarkdownPlugin.ts and the Markdown docs page describe both.
  • The change adds two tests in deserializer/deserializeMd.spec.ts and a patch changeset.

Tradeoffs

  • The key check applies to disallowedNodes only. Checking allowlists by key would drop <br> and <span> text from allowlists that admit mdxJsxTextElement, since keys like br and span have no plugin to list.
  • A table-cell list whose blocked block child the filter removes now converts instead of falling back to text. It keeps only what the filters allow.

Blast Radius

The change affects only deserializeMd calls that use remark-mdx and a non-empty disallowedNodes. Markdown nested in **, * and ~~ still skips the node filters, as on main; #5142 tracks that gap.

Verification

  • removes inline html elements whose deserialize rule key is disallowed fails without the new check and passes with it. keeps inline html under an allowlist that admits mdxJsxTextElement pins the allowlist behavior.
  • pnpm --filter @platejs/markdown test: 274 pass. pnpm check: exit 0 (Biome, 54 typecheck tasks, 3,569 fast tests plus the slow suites).

With remark-mdx, the node filters saw an inline HTML element only as
mdxJsxTextElement, so disallowedNodes: ['a'] dropped Markdown links but
kept <a href> anchors. customMdxDeserialize now removes an element whose
deserialize rule key is listed in disallowedNodes before the rule runs.
allowedNodes keeps its behavior: mdxJsxTextElement admits inline HTML and
MDX elements and mdxJsxFlowElement admits block ones.
@zbeyens
zbeyens requested a review from a team October 3, 2026 12:42
@codesandbox

codesandbox Bot commented Oct 3, 2026

Copy link
Copy Markdown

Review or Edit in CodeSandbox

Open the branch in Web Editor • VS Code • Insiders

Open Preview

@changeset-bot

changeset-bot Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 5ee4bd4

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@platejs/markdown Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-03T12:45:20.289469Z 0a53bb8 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: allowedNodes and disallowedNodes do not filter inline HTML elements by their Plate type

1 participant