From 4609d93faf0cf71d1ccdc0d25bbce183d29bea04 Mon Sep 17 00:00:00 2001 From: iamdoubz <> Date: Thu, 2 Jul 2026 07:44:41 -0500 Subject: [PATCH] refactor(ui): extract shared sanitized-Markdown renderer (T7.1) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Notes and LLM-generated summaries both render untrusted Markdown via {@html} into a webview with an IPC bridge to the Rust backend, so the DOMPurify sanitization step is a real security boundary, not cosmetic — worth one shared implementation instead of a second inline copy that could drift out of sync. --- src/lib/markdown.ts | 11 +++++++++++ 1 file changed, 11 insertions(+) create mode 100644 src/lib/markdown.ts diff --git a/src/lib/markdown.ts b/src/lib/markdown.ts new file mode 100644 index 0000000..7cebaee --- /dev/null +++ b/src/lib/markdown.ts @@ -0,0 +1,11 @@ +// Shared Markdown rendering for any Markdown that isn't guaranteed to be our +// own trusted output (notes, LLM-generated summaries) — this webview has an +// IPC bridge to the Rust backend, so unsanitized `{@html}` here would be a +// real local-privilege risk, not just a cosmetic one. Kept in one place so a +// future sanitization fix can't miss a second copy. +import { marked } from "marked"; +import DOMPurify from "dompurify"; + +export function renderMarkdown(markdown: string): string { + return DOMPurify.sanitize(marked.parse(markdown || "") as string); +}