Upgrade code
This commit is contained in:
@@ -219,9 +219,10 @@ def notify_comment_added(comment):
|
||||
# receive the new comment immediately without needing to reload.
|
||||
payload = {
|
||||
'id' : comment.id,
|
||||
'author_name': comment.author.full_name,
|
||||
'author_init': comment.author.full_name[0].upper(),
|
||||
'is_it_staff': comment.author.is_it_staff,
|
||||
'author_name' : comment.author.full_name,
|
||||
'author_init' : comment.author.full_name[0].upper(),
|
||||
'author_avatar': comment.author.avatar_url or '',
|
||||
'is_it_staff' : comment.author.is_it_staff,
|
||||
'is_internal': comment.is_internal,
|
||||
'body' : comment.body,
|
||||
'created_at' : comment.created_at.strftime('%b %d, %Y %H:%M'),
|
||||
|
||||
@@ -6,6 +6,7 @@ copy-pasting validation code into auth.py, admin.py, and future modules.
|
||||
"""
|
||||
|
||||
import logging
|
||||
import mistune
|
||||
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
@@ -177,3 +178,51 @@ def _group_by_alternative(
|
||||
else:
|
||||
groups.append([(offset, magic)])
|
||||
return groups if groups else [[]]
|
||||
|
||||
|
||||
# ─── Comment Body Markdown Rendering ─────────────────────────────────────────
|
||||
# Comments support a safe subset of Markdown (bold, italic, code, lists,
|
||||
# blockquotes, links). We render to HTML at write time and sanitize with a
|
||||
# strict allowlist so stored bodies are always safe to render with | safe.
|
||||
#
|
||||
# Intentionally excluded from comments (present in KB allowlist):
|
||||
# img, table, div, h1-h6, figure — keep comment rendering lightweight.
|
||||
|
||||
import bleach as _bleach
|
||||
|
||||
_COMMENT_ALLOWED_TAGS = {
|
||||
'p', 'br',
|
||||
'strong', 'em', 'u', 's', 'code', 'pre',
|
||||
'ul', 'ol', 'li',
|
||||
'blockquote',
|
||||
'a',
|
||||
'hr',
|
||||
}
|
||||
_COMMENT_ALLOWED_ATTRS = {
|
||||
'a': ['href', 'title', 'rel'],
|
||||
}
|
||||
|
||||
_md = mistune.create_markdown(escape=True)
|
||||
|
||||
|
||||
def render_comment_body(raw_text: str) -> str:
|
||||
"""Convert plain-text Markdown comment to sanitized HTML.
|
||||
|
||||
Renders Markdown to HTML with mistune, then strips any tags/attributes
|
||||
not in the comment allowlist via bleach. The result is safe to render
|
||||
with Jinja2's ``| safe`` filter without further escaping.
|
||||
|
||||
Parameters
|
||||
----------
|
||||
raw_text : str – the raw plain-text comment body submitted by the user
|
||||
"""
|
||||
if not raw_text:
|
||||
return ''
|
||||
html = _md(raw_text)
|
||||
cleaned = _bleach.clean(
|
||||
html,
|
||||
tags = _COMMENT_ALLOWED_TAGS,
|
||||
attributes = _COMMENT_ALLOWED_ATTRS,
|
||||
strip = True,
|
||||
)
|
||||
return cleaned
|
||||
|
||||
Reference in New Issue
Block a user