Repository navigation
Render post, page and comment bodies from the server - #3
Merged
Merged
Conversation
goblog v0.10.0 renders markdown server-side, so the theme drops its
showdown and DOMPurify script tags and renders {{ .post.HTML }},
{{ .page.HTML }} and each comment's {{ .HTML }} instead. The post body
now reaches crawlers and link-preview bots, and the YouTube and
Instagram embeds DOMPurify used to strip work again.
The comment Preview button shows the draft as plain text, since no
markdown library is loaded on the page any more.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The updated plain-text comment preview should preserve user-entered line breaks (whitespace) to avoid a misleading preview experience.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
What changed in this PR
This PR shifts post, page, and comment body rendering from client-side JavaScript (Showdown + DOMPurify) to server-rendered HTML provided by goblog v0.10.0, improving embed support and non-JS rendering (crawlers/reader mode/link previews).
Changes:
- Render post and comment bodies directly from server-provided HTML in
templates/post.html, removing client-side markdown rendering and sanitization scripts. - Render page bodies directly from server-provided HTML in
templates/page_content.html(non-plugin path), removing client-side rendering scripts. - Bump minimum supported goblog version to
0.10.0and document the change inCHANGELOG.md.
| File | Description |
|---|---|
| templates/post.html | Server-renders post/comment HTML; removes Showdown/DOMPurify and adjusts comment preview behavior |
| templates/page_content.html | Server-renders page HTML (non-plugin path); removes Showdown/DOMPurify |
| goblog-theme.json | Raises min_goblog_version to 0.10.0 |
| CHANGELOG.md | Adds 1.2.0 entry describing server-rendering and version requirement |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
194
to
198
| function previewComment() { | ||
| var content = document.getElementById("comment-content").value; | ||
| var preview = document.getElementById("comment-preview"); | ||
| if (typeof converter !== 'undefined') { | ||
| preview.innerHTML = DOMPurify.sanitize(converter.makeHtml(content)); | ||
| } else { | ||
| preview.textContent = content; | ||
| } | ||
| preview.textContent = content; | ||
| preview.style.display = "block"; |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Requires goblog v0.10.0 (goblogplatform/GoBlog#627) —
min_goblog_versionis bumped to0.10.0, so the installer refuses this version on an older goblog rather than serving blank post bodies.Summary
post.html: the body renders{{ .post.HTML }}, each comment renders{{ .HTML }}, and the showdown + DOMPurify script tags, the<noscript>fallbacks and the per-comment rendering script are gone.page_content.html: the body renders{{ .page.HTML }}; the plugin-content branch is untouched.goblog-theme.json→min_goblog_version: 0.10.0; CHANGELOG entry for 1.2.0.Why
DOMPurify was stripping every
<iframe>and<script>from post bodies client-side, so YouTube and Instagram embeds were silently broken. They work again. And anything that does not run JavaScript — link previews, most crawlers, reader modes — now sees the post rather than raw markdown.Verification
Rendered through goblog v0.10.0 with a real post carrying three YouTube embeds and a malicious comment:
The comment's
<script>alert(1)</script>does not reach the page; its markdown renders.Mirrors goblogplatform/goblog-site-theme#10.
🤖 Generated with Claude Code