diff options
| author | grm <grm@eyesin.space> | 2026-09-16 18:37:20 +0300 |
|---|---|---|
| committer | grm <grm@eyesin.space> | 2026-09-16 18:37:20 +0300 |
| commit | 6b6b5d2e35ff182a0732da245f4eb37c8afa0564 (patch) | |
| tree | f56960ae86c3c289f9a68e38ec01f1e3ff997466 /internal/web/handlers_files.go | |
| parent | 5119018feeaa22c47c0e91e15d3b9414dd6e0772 (diff) | |
| download | blogspace-6b6b5d2e35ff182a0732da245f4eb37c8afa0564.tar.gz blogspace-6b6b5d2e35ff182a0732da245f4eb37c8afa0564.tar.bz2 blogspace-6b6b5d2e35ff182a0732da245f4eb37c8afa0564.zip | |
Add an HTML mode to posts, page intros and announcements
Markdown is the default and unchanged; the editor's new Format switch
stores the text as raw HTML instead, put on the blog exactly as written.
Like the custom HTML module it is unsanitised on purpose: the escape
hatch for embeds, scripts and inline styles that Markdown cannot express.
The source column keeps holding the text in both modes and a `format`
column says how to read it, so the public templates and the feed still
print the stored `*_html`. The dashboard preview of HTML goes into a
sandboxed iframe rather than the page, because a superadmin edits other
people's blogs and their markup must never run on the dashboard origin.
Search snippets of HTML posts are cut from a tag-stripped copy.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'internal/web/handlers_files.go')
| -rw-r--r-- | internal/web/handlers_files.go | 45 |
1 files changed, 36 insertions, 9 deletions
diff --git a/internal/web/handlers_files.go b/internal/web/handlers_files.go index 1d90b91..2b68871 100644 --- a/internal/web/handlers_files.go +++ b/internal/web/handlers_files.go @@ -4,6 +4,7 @@ import ( "bytes" "encoding/json" "errors" + "html" "io" "mime/multipart" "net/http" @@ -12,6 +13,7 @@ import ( "strings" "github.com/google/uuid" + "github.com/gramanas/blogspace/internal/markdown" "github.com/gramanas/blogspace/internal/store" ) @@ -71,17 +73,42 @@ func fileMarkdown(f *store.File) string { return open + text + "](/media/" + f.ID.String() + ")" } -// appendFileMD is the no-JavaScript path of "Insert file": the file arrives -// with the form itself and is appended to the end of the text on save. -func appendFileMD(md string, f *store.File) string { +// fileHTML is fileMarkdown for content written in HTML mode. +func fileHTML(f *store.File) string { + name := html.EscapeString(f.Filename) + src := "/media/" + f.ID.String() + if f.Kind == "image" { + return `<img src="` + src + `" alt="` + name + `">` + } + return `<a href="` + src + `">` + name + `</a>` +} + +// appendFile is the no-JavaScript path of "Insert file": the file arrives +// with the form itself and is appended to the end of the text on save, in +// the text's format. +func appendFile(body string, f *store.File, format string) string { if f == nil { - return md + return body } - md = strings.TrimRight(md, "\n") - if md != "" { - md += "\n\n" + line := fileMarkdown(f) + if format == store.FormatHTML { + line = fileHTML(f) + } + body = strings.TrimRight(body, "\n") + if body != "" { + body += "\n\n" + } + return body + line + "\n" +} + +// renderBody is what a save stores for the blog to show: Markdown is rendered +// and sanitised, HTML goes out exactly as the blogger wrote it — the same +// owner's decision as the custom HTML module (see AGENTS.md). +func renderBody(format, src string) string { + if format == store.FormatHTML { + return src } - return md + fileMarkdown(f) + "\n" + return markdown.Render(src) } // ---- file library ---------------------------------------------------------- @@ -182,7 +209,7 @@ func (s *Server) handleFileUpload(w http.ResponseWriter, r *http.Request) { return } f := files[0] - writeJSON(w, http.StatusOK, map[string]any{"id": f.ID.String(), "filename": f.Filename, "kind": f.Kind, "size": f.Size, "markdown": fileMarkdown(f)}) + writeJSON(w, http.StatusOK, map[string]any{"id": f.ID.String(), "filename": f.Filename, "kind": f.Kind, "size": f.Size, "markdown": fileMarkdown(f), "html": fileHTML(f)}) return } if msg != "" { |
