aboutsummaryrefslogtreecommitdiffstats
path: root/internal/markdown/render.go
diff options
context:
space:
mode:
authorgramanas <grm@eyesin.space>2026-09-12 11:24:17 +0300
committergramanas <grm@eyesin.space>2026-09-12 11:24:17 +0300
commit3eb04b1a2bdf9e53231fe862cfd76327371a9741 (patch)
treeb38b2d82a47233fd8e0bb18c59e4a8f3dd2412d7 /internal/markdown/render.go
downloadblogspace-3eb04b1a2bdf9e53231fe862cfd76327371a9741.tar.gz
blogspace-3eb04b1a2bdf9e53231fe862cfd76327371a9741.tar.bz2
blogspace-3eb04b1a2bdf9e53231fe862cfd76327371a9741.zip
Initial multi-tenant blog host
Go + Postgres application serving a management dashboard on the base domain and one public blog per subdomain. Markdown posts organised in pages, form-based theme customisation, image uploads stored in Postgres, JWT cookie sessions with CSRF, superadmin user management, RSS feeds. Docker/compose deployment and a Makefile-driven dev environment with seed data. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'internal/markdown/render.go')
-rw-r--r--internal/markdown/render.go38
1 files changed, 38 insertions, 0 deletions
diff --git a/internal/markdown/render.go b/internal/markdown/render.go
new file mode 100644
index 0000000..f9a2bfd
--- /dev/null
+++ b/internal/markdown/render.go
@@ -0,0 +1,38 @@
+// Package markdown renders untrusted Markdown to sanitized HTML.
+package markdown
+
+import (
+ "bytes"
+
+ "github.com/microcosm-cc/bluemonday"
+ "github.com/yuin/goldmark"
+ "github.com/yuin/goldmark/extension"
+ "github.com/yuin/goldmark/parser"
+ "github.com/yuin/goldmark/renderer/html"
+)
+
+var md = goldmark.New(
+ goldmark.WithExtensions(extension.GFM, extension.Typographer),
+ goldmark.WithParserOptions(parser.WithAutoHeadingID()),
+ goldmark.WithRendererOptions(html.WithHardWraps(), html.WithUnsafe()), // unsafe output is sanitized below
+)
+
+var policy = func() *bluemonday.Policy {
+ p := bluemonday.UGCPolicy()
+ p.AllowAttrs("id").OnElements("h1", "h2", "h3", "h4", "h5", "h6")
+ p.AllowAttrs("class").Matching(bluemonday.SpaceSeparatedTokens).OnElements("code", "pre", "span", "div", "table", "input", "li", "ul")
+ p.AllowAttrs("type", "checked", "disabled").OnElements("input")
+ p.AllowAttrs("align").OnElements("th", "td")
+ p.AllowAttrs("width", "height").OnElements("img")
+ p.RequireNoFollowOnLinks(false)
+ return p
+}()
+
+// Render converts Markdown to HTML that is safe to embed unescaped.
+func Render(src string) string {
+ var buf bytes.Buffer
+ if err := md.Convert([]byte(src), &buf); err != nil {
+ return "<p>(could not render content)</p>"
+ }
+ return policy.Sanitize(buf.String())
+}