Skip to content

Render post, page and comment bodies from the server - #3

Merged
compscidr merged 1 commit into
mainfrom
feat/617-server-side-markdown
Sep 23, 2026
Merged

compscidr merged 1 commit into
mainfrom
feat/617-server-side-markdown

Conversation

@compscidr

Copy link
Copy Markdown
Contributor

Requires goblog v0.10.0 (goblogplatform/GoBlog#627) — min_goblog_version is bumped to 0.10.0, so the installer refuses this version on an older goblog rather than serving blank post bodies.

Summary

  • post.html: the body renders {{ .post.HTML }}, each comment renders {{ .HTML }}, and the showdown + DOMPurify script tags, the <noscript> fallbacks and the per-comment rendering script are gone.
  • page_content.html: the body renders {{ .page.HTML }}; the plugin-content branch is untouched.
  • The comment Preview button shows the draft as plain text — no markdown library is loaded on the page any more.
  • goblog-theme.json → min_goblog_version: 0.10.0; CHANGELOG entry for 1.2.0.

Why

DOMPurify was stripping every <iframe> and <script> from post bodies client-side, so YouTube and Instagram embeds were silently broken. They work again. And anything that does not run JavaScript — link previews, most crawlers, reader modes — now sees the post rather than raw markdown.

Verification

Rendered through goblog v0.10.0 with a real post carrying three YouTube embeds and a malicious comment:

post page: iframes=3 showdown=0 purify=0 strong=2 noscript=0
about page: strong=1 showdown=0

The comment's <script>alert(1)</script> does not reach the page; its markdown renders.

Mirrors goblogplatform/goblog-site-theme#10.

🤖 Generated with Claude Code

goblog v0.10.0 renders markdown server-side, so the theme drops its
showdown and DOMPurify script tags and renders {{ .post.HTML }},
{{ .page.HTML }} and each comment's {{ .HTML }} instead. The post body
now reaches crawlers and link-preview bots, and the YouTube and
Instagram embeds DOMPurify used to strip work again.

The comment Preview button shows the draft as plain text, since no
markdown library is loaded on the page any more.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 23, 2026 02:54
@compscidr
compscidr merged commit 73b764b into main Sep 23, 2026
1 check passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The updated plain-text comment preview should preserve user-entered line breaks (whitespace) to avoid a misleading preview experience.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
What changed in this PR

This PR shifts post, page, and comment body rendering from client-side JavaScript (Showdown + DOMPurify) to server-rendered HTML provided by goblog v0.10.0, improving embed support and non-JS rendering (crawlers/reader mode/link previews).

Changes:

  • Render post and comment bodies directly from server-provided HTML in templates/post.html, removing client-side markdown rendering and sanitization scripts.
  • Render page bodies directly from server-provided HTML in templates/page_content.html (non-plugin path), removing client-side rendering scripts.
  • Bump minimum supported goblog version to 0.10.0 and document the change in CHANGELOG.md.
File Description
templates/​post.html Server-renders post/comment HTML; removes Showdown/DOMPurify and adjusts comment preview behavior
templates/​page_content.html Server-renders page HTML (non-plugin path); removes Showdown/DOMPurify
goblog-theme.json Raises min_goblog_version to 0.10.0
CHANGELOG.md Adds 1.2.0 entry describing server-rendering and version requirement

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread templates/post.html
Comment on lines 194 to 198
function previewComment() {
var content = document.getElementById("comment-content").value;
var preview = document.getElementById("comment-preview");
if (typeof converter !== 'undefined') {
preview.innerHTML = DOMPurify.sanitize(converter.makeHtml(content));
} else {
preview.textContent = content;
}
preview.textContent = content;
preview.style.display = "block";
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants