feat(frontend): save project descriptions as HTML alongside markdown (#90) - #1002
Merged
github-actions[bot] merged 1 commit intoSep 29, 2026
Conversation
…martdevs17#90) The rich text editor (issue Smartdevs17#795) stored descriptions as markdown only, so the "save as HTML" acceptance criterion was unmet and consumers that cannot render markdown had nothing to display. - lib/markdown/to-html.ts: dependency-free markdown -> HTML serializer covering the subset the editor produces (headings, emphasis, strikethrough, inline and fenced code, links, images, lists, quotes, rules). Raw HTML is never passed through and only http/https/mailto URLs are emitted, so hostile input cannot introduce markup or script. - lib/projects/work-description.ts: builds the on-chain `workDescription` payload with both `description` (markdown) and `descriptionHtml`, used by /dashboard/projects/new and its localized variant so the shape stays in sync. - RichTextEditor: add an HTML view toggle with Copy HTML, alongside the existing preview toggle. - docs: document the HTML rendition, the payload shape and the security posture. 🤖 Generated with Codebuff Co-Authored-By: Codebuff <noreply@codebuff.com>
|
@sandrawillow001-afk is attempting to deploy a commit to the smartdevs17's projects Team on Vercel. A member of the Team first needs to authorize it. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #90.
What already existed
The rich text editor from #795 (
components/markdown/RichTextEditor.tsx) already covered three of the four acceptance criteria — rich text editing, formatting and image support — storing markdown as the source of truth.Gap closed: "save as HTML"
lib/markdown/to-html.ts— markdown → HTML serializer covering the subset the editor can produce: headings, bold/italic/strikethrough, inline and fenced code, links, images, lists, block quotes and rules.lib/projects/work-description.ts— builds the on-chainworkDescriptionpayload with bothdescription(markdown) anddescriptionHtml. Both/dashboard/projects/newand/[locale]/dashboard/projects/newnow call this helper, so the contract shape stays in sync.Security posture
The conversion is dependency-free and never passes raw HTML through: every text run is escaped (
<script>→<script>), onlyhttp:/https:/mailto:URLs are emitted, andjavascript:,data:,vbscript:and protocol-relative URLs are dropped. External links getrel="noopener noreferrer"; images getloading="lazy".Why not
react-markdownfor thisThe preview renders through
react-markdown, but the project has no markdown stringifier dependency (rehype-stringify), and adding one purely for this feature would be a heavier change than it warrants.Verification
Finding not addressed here (pre-existing, worth a follow-up)
The frontend component test suite cannot run on
main:@testing-library/react,@testing-library/user-eventand@testing-library/jest-domare imported by ~8 test files (includingvitest.setup.ts) and by the merged #795 editor test, but are not declared infrontend/package.json, andvitest.config.tsnever setssetupFiles, sovitest.setup.tsis dead. I kept this PR free of test-infrastructure churn; declaring those devDependencies and wiringsetupFiles: ['./vitest.setup.ts']is a separate change (it unblocks those files, though ~5 of them then fail for unrelated pre-existing reasons).🤖 Generated with Codebuff