Adopt marked + DOMPurify for markdown rendering (D-WEB-7) #174
Labels
No labels
actions
bug
cli
duplicate
enhancement
fork
forum
git storage
help wanted
insights
invalid
issues
moderation
oidc
ownership transfer
packages
pr/merge protection rules
projects
pull requests
question
releases
sponsorships
tags
webhooks
wiki
wontfix
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
crueber/walhub#174
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Adopt marked + DOMPurify for markdown rendering (D-WEB-7)
Approved direction (user, 2026-09-06; investigation in
/tmp/opencode/markdown-options.md): replace the hand-rolled markdown-lite renderer (web/src/lib/markdown.js) and allowlist sanitizer (web/src/lib/sanitize.js) withmarked@18.0.11(MIT) +dompurify@3.4.15(MPL-2.0-or-Apache-2.0), both zero-dependency (+24.0 KB gzip measured with the repo's esbuild).Amendment (lands in DEVIATIONS.md + AGENTS.md law-1 line in the same change)
Migration (per investigation §8)
web/src/lib/render-md.js(markedGFM + pinned DOMPurify config incl.del,s,input,checked/disabled/type/class); exportrenderBody(src).innerHTML={renderBody(...)}(Blob, Tree, Release, IssueNew, ThreadTimeline). No shape change.markdown.js+sanitize.jsin the same change (pre-1.0 rule).markdown.test.jsagainstrender-md.js— marked layer innode --test(option (a): DOMPurify path covered by the real-Chromium pass, not Node); preserve all current assertions + new: strikethrough, task checkboxes (disabled),javascript:dropped,<script>dropped, bare-URL autolink. Conscious choice required: marked emits<code class="language-js">vs current<code data-lang>— map back or update CSS/tests.make test-web,make web, bundle delta ≤ ~25 KB gzip note in commit, real-browser pass (/, task-list/table comment,/setup, console clean).Acceptance criteria
package.json+ bundle metafile).node --testgreen;make webclean; browser pass dark + light, zero console errors.PR #175 ready for review: #175 — marked@18.0.11 + dompurify@3.4.15 behind render-md.js; 363/363 node green, make web clean, Chromium 14/14 + zero console errors, bundle +22.2 KB gzip. Not merging per instructions.
REVIEW PR #175 (feat/issue-174, commit
4f270f5) — verified in scratch worktrees (since removed); main worktree untouched (still clean on main apart from pre-existing untracked .opencode/).AMENDMENT / DOCS
SANITIZER AUDIT (web/src/lib/render-md.js:31-42) — PASS
OTHER CHECKS
contract); data-lang has zero CSS/JS consumers (grep) — language-* mapping sound.
TESTS
MERGE RECOMMENDATION: ready to merge (no fixes pushed — nothing blocking found).
Implemented in PR #175 (review: sanitizer audited line-by-line + 30-probe browser XSS drive, all stripped; +22.18 KB gzip; 363/363), merged. Closing.