From 6b6b5d2e35ff182a0732da245f4eb37c8afa0564 Mon Sep 17 00:00:00 2001 From: grm Date: Wed, 16 Sep 2026 18:37:20 +0300 Subject: Add an HTML mode to posts, page intros and announcements Markdown is the default and unchanged; the editor's new Format switch stores the text as raw HTML instead, put on the blog exactly as written. Like the custom HTML module it is unsanitised on purpose: the escape hatch for embeds, scripts and inline styles that Markdown cannot express. The source column keeps holding the text in both modes and a `format` column says how to read it, so the public templates and the feed still print the stored `*_html`. The dashboard preview of HTML goes into a sandboxed iframe rather than the page, because a superadmin edits other people's blogs and their markup must never run on the dashboard origin. Search snippets of HTML posts are cut from a tag-stripped copy. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A --- internal/web/search.go | 21 +++++++++++++++++++-- 1 file changed, 19 insertions(+), 2 deletions(-) (limited to 'internal/web/search.go') diff --git a/internal/web/search.go b/internal/web/search.go index ef554ae..9af980d 100644 --- a/internal/web/search.go +++ b/internal/web/search.go @@ -1,11 +1,14 @@ package web import ( + "html" "html/template" "regexp" "strings" "unicode/utf8" + "github.com/microcosm-cc/bluemonday" + "github.com/gramanas/blogspace/internal/store" ) @@ -32,8 +35,22 @@ type searchHit struct { Snippet template.HTML } -// searchSnippet is a short piece of the Markdown body around the first match, -// with the match marked; when only the title matched it is the body's start. +var stripTags = bluemonday.StrictPolicy() + +// snippetSource is the text a post's snippet is cut from: the Markdown as +// written, or an HTML post with its tags stripped so the excerpt reads as +// prose. (Postgres still matches against the source, so a query can hit a +// tag or attribute name in an HTML post; the snippet then shows the text +// nearest to it.) +func snippetSource(p *store.Post) string { + if p.Format == store.FormatHTML { + return html.UnescapeString(stripTags.Sanitize(p.BodyMD)) + } + return p.BodyMD +} + +// searchSnippet is a short piece of the body around the first match, with the +// match marked; when only the title matched it is the body's start. func searchSnippet(body string, re *regexp.Regexp) template.HTML { text := strings.Join(strings.Fields(body), " ") loc := re.FindStringIndex(text) -- cgit v1.2.3