diff --git a/src/lib/markdown.ts b/src/lib/markdown.ts new file mode 100644 index 0000000..7cebaee --- /dev/null +++ b/src/lib/markdown.ts @@ -0,0 +1,11 @@ +// Shared Markdown rendering for any Markdown that isn't guaranteed to be our +// own trusted output (notes, LLM-generated summaries) — this webview has an +// IPC bridge to the Rust backend, so unsanitized `{@html}` here would be a +// real local-privilege risk, not just a cosmetic one. Kept in one place so a +// future sanitization fix can't miss a second copy. +import { marked } from "marked"; +import DOMPurify from "dompurify"; + +export function renderMarkdown(markdown: string): string { + return DOMPurify.sanitize(marked.parse(markdown || "") as string); +}