aboutsummaryrefslogtreecommitdiffstats
path: root/internal/web/search.go
diff options
context:
space:
mode:
authorgrm <grm@eyesin.space>2026-09-16 18:37:20 +0300
committergrm <grm@eyesin.space>2026-09-16 18:37:20 +0300
commit6b6b5d2e35ff182a0732da245f4eb37c8afa0564 (patch)
treef56960ae86c3c289f9a68e38ec01f1e3ff997466 /internal/web/search.go
parent5119018feeaa22c47c0e91e15d3b9414dd6e0772 (diff)
downloadblogspace-6b6b5d2e35ff182a0732da245f4eb37c8afa0564.tar.gz
blogspace-6b6b5d2e35ff182a0732da245f4eb37c8afa0564.tar.bz2
blogspace-6b6b5d2e35ff182a0732da245f4eb37c8afa0564.zip
Add an HTML mode to posts, page intros and announcements
Markdown is the default and unchanged; the editor's new Format switch stores the text as raw HTML instead, put on the blog exactly as written. Like the custom HTML module it is unsanitised on purpose: the escape hatch for embeds, scripts and inline styles that Markdown cannot express. The source column keeps holding the text in both modes and a `format` column says how to read it, so the public templates and the feed still print the stored `*_html`. The dashboard preview of HTML goes into a sandboxed iframe rather than the page, because a superadmin edits other people's blogs and their markup must never run on the dashboard origin. Search snippets of HTML posts are cut from a tag-stripped copy. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'internal/web/search.go')
-rw-r--r--internal/web/search.go21
1 files changed, 19 insertions, 2 deletions
diff --git a/internal/web/search.go b/internal/web/search.go
index ef554ae..9af980d 100644
--- a/internal/web/search.go
+++ b/internal/web/search.go
@@ -1,11 +1,14 @@
package web
import (
+ "html"
"html/template"
"regexp"
"strings"
"unicode/utf8"
+ "github.com/microcosm-cc/bluemonday"
+
"github.com/gramanas/blogspace/internal/store"
)
@@ -32,8 +35,22 @@ type searchHit struct {
Snippet template.HTML
}
-// searchSnippet is a short piece of the Markdown body around the first match,
-// with the match marked; when only the title matched it is the body's start.
+var stripTags = bluemonday.StrictPolicy()
+
+// snippetSource is the text a post's snippet is cut from: the Markdown as
+// written, or an HTML post with its tags stripped so the excerpt reads as
+// prose. (Postgres still matches against the source, so a query can hit a
+// tag or attribute name in an HTML post; the snippet then shows the text
+// nearest to it.)
+func snippetSource(p *store.Post) string {
+ if p.Format == store.FormatHTML {
+ return html.UnescapeString(stripTags.Sanitize(p.BodyMD))
+ }
+ return p.BodyMD
+}
+
+// searchSnippet is a short piece of the body around the first match, with the
+// match marked; when only the title matched it is the body's start.
func searchSnippet(body string, re *regexp.Regexp) template.HTML {
text := strings.Join(strings.Fields(body), " ")
loc := re.FindStringIndex(text)