diff options
| author | grm <grm@eyesin.space> | 2026-09-16 18:37:20 +0300 |
|---|---|---|
| committer | grm <grm@eyesin.space> | 2026-09-16 18:37:20 +0300 |
| commit | 6b6b5d2e35ff182a0732da245f4eb37c8afa0564 (patch) | |
| tree | f56960ae86c3c289f9a68e38ec01f1e3ff997466 /internal/web/search_test.go | |
| parent | 5119018feeaa22c47c0e91e15d3b9414dd6e0772 (diff) | |
| download | blogspace-6b6b5d2e35ff182a0732da245f4eb37c8afa0564.tar.gz blogspace-6b6b5d2e35ff182a0732da245f4eb37c8afa0564.tar.bz2 blogspace-6b6b5d2e35ff182a0732da245f4eb37c8afa0564.zip | |
Add an HTML mode to posts, page intros and announcements
Markdown is the default and unchanged; the editor's new Format switch
stores the text as raw HTML instead, put on the blog exactly as written.
Like the custom HTML module it is unsanitised on purpose: the escape
hatch for embeds, scripts and inline styles that Markdown cannot express.
The source column keeps holding the text in both modes and a `format`
column says how to read it, so the public templates and the feed still
print the stored `*_html`. The dashboard preview of HTML goes into a
sandboxed iframe rather than the page, because a superadmin edits other
people's blogs and their markup must never run on the dashboard origin.
Search snippets of HTML posts are cut from a tag-stripped copy.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'internal/web/search_test.go')
| -rw-r--r-- | internal/web/search_test.go | 13 |
1 files changed, 13 insertions, 0 deletions
diff --git a/internal/web/search_test.go b/internal/web/search_test.go index 6a9b0a5..6ced39b 100644 --- a/internal/web/search_test.go +++ b/internal/web/search_test.go @@ -4,6 +4,8 @@ import ( "regexp" "strings" "testing" + + "github.com/gramanas/blogspace/internal/store" ) func TestSearchPattern(t *testing.T) { @@ -42,3 +44,14 @@ func TestSearchSnippet(t *testing.T) { t.Errorf("title-only snippet: %q", got) } } + +func TestSnippetSource(t *testing.T) { + p := &store.Post{Format: store.FormatHTML, BodyMD: `<p class="x">Tom & <b>Jerry</b></p><script>alert(1)</script>`} + if got := snippetSource(p); got != "Tom & Jerry" { + t.Errorf("html post: %q", got) + } + p.Format = store.FormatMarkdown + if got := snippetSource(p); got != p.BodyMD { + t.Errorf("markdown post is used as written: %q", got) + } +} |
