Group-membership Notes and several other Notes displays showed raw Markdown or plain text while existing Notes supported formatting. This change applies consistent Markdown rendering across catalog details, related tables, appearance and reprint annotations, collection items, and other Notes displays.
Shared rich_text.html and notes.html partials, a reusable MarkdownColumn, and common block/inline renderers replace duplicated rendering patterns, including existing biographies and descriptions. Source text remains unchanged for exports and revision diffs. Inline annotations retain valid HTML, and rendered content no longer receives duplicate line-break conversion.
Rendering and Markdownx previews share an allowlist sanitizer. Display rendering sanitizes unconditionally before marking HTML safe. This adds nh3>=0.3,<0.4; deployments must install the updated requirements. Supported formatting is retained, while scripts, event handlers, unsafe URL schemes, and arbitrary styles are removed. No database migration or source-data conversion is required.
Validation:
The full test suite and production content were not validated. Existing Django and pygraph/pkg_resources deprecation warnings are tracked separately.
https://github.com/GrandComicsDatabase/gcd-django/pull/769
(84 files)
—
Reply to this email directly, view it on GitHub, or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
I noticed this problem after this edit was discarded: https://www.comics.org/changeset/8521014/compare/
—
Reply to this email directly, view it on GitHub, or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
@gemini-code-assist[bot] commented on this pull request.
This pull request refactors the Markdown rendering system by introducing the nh3 library for HTML sanitization and defining separate render_markdown and render_markdown_inline functions to handle block and inline formatting safely. It updates numerous models, template tags, and templates to utilize these functions, and adds a comprehensive test suite. The review feedback highlights several instances where using render_markdown inside list items (
In apps/gcd/templatetags/credits.py:
> @@ -324,7 +319,7 @@ def __format_credit(story, credit, computed_value='', tailwind=False,
values = split_reprint_string(credit_value)
credit_value = '<ul>'
for value in values:
- credit_value += '<li>' + esc(value)
+ credit_value += '<li>' + render_markdown(value)
Using render_markdown inside list items (<li>) wraps the content in block-level <p class="pt-4"> tags, which introduces unwanted top padding and margins. Since these are compact list items, consider using render_markdown_inline instead to keep the list layout clean and compact.
- credit_value += '<li>' + render_markdown(value) + credit_value += '<li>' + render_markdown_inline(value)
In apps/gcd/templatetags/credits.py:
> + reprint_note += ('<li> ' + render_markdown(string) +
+ ' </li>')
Using render_markdown inside <li> wraps the reprint notes in block-level <p class="pt-4"> tags, which adds unwanted vertical spacing in the list. Consider using render_markdown_inline to keep the reprint notes compact.
reprint_note += ('<li> ' + render_markdown_inline(string) +\n ' </li>')
In apps/gcd/templatetags/credits.py:
> + reprint_note += ('<li> ' + render_markdown(string) +
+ ' </li>')
Using render_markdown inside <li> wraps the reprint notes in block-level <p class="pt-4"> tags, which adds unwanted vertical spacing in the list. Consider using render_markdown_inline to keep the reprint notes compact.
reprint_note += ('<li> ' + render_markdown_inline(string) +\n ' </li>')
In apps/gcd/templatetags/credits.py:
> @@ -877,7 +865,7 @@ def show_reprints(story, bare_value=False):
if story.reprint_notes:
for string in split_reprint_string(story.reprint_notes):
string = string.strip()
- reprint += '<li> ' + esc(string) + ' </li>'
+ reprint += '<li> ' + render_markdown(string) + ' </li>'
Using render_markdown inside <li> wraps the reprint notes in block-level <p class="pt-4"> tags, which adds unwanted vertical spacing in the list. Consider using render_markdown_inline to keep the reprint notes compact.
- reprint += '<li> ' + render_markdown(string) + ' </li>' + reprint += '<li> ' + render_markdown_inline(string) + ' </li>'
In apps/oi/templatetags/compare.py:
> @@ -12,8 +12,9 @@
sum_page_counts, show_barcode, \
show_isbn
from apps.gcd.templatetags.credits import format_page_count, \
- split_reprint_string, \
- render_markdown
+ split_reprint_string
+
+from apps.gcd.markdown_extension import render_markdown
Import render_markdown_inline from apps.gcd.markdown_extension to support rendering reprint notes compactly in the comparison view.
-from apps.gcd.markdown_extension import render_markdown +from apps.gcd.markdown_extension import render_markdown, render_markdown_inline
In apps/oi/templatetags/compare.py:
> elif field == 'reprint_notes':
reprint = ''
if value.strip() != '':
for string in split_reprint_string(value):
string = string.strip()
- reprint += '<li> ' + esc(string) + ' </li>'
+ reprint += '<li> ' + render_markdown(string) + ' </li>'
Using render_markdown inside <li> wraps the reprint notes in block-level <p class="pt-4"> tags, which adds unwanted vertical spacing in the list. Consider using render_markdown_inline to keep the reprint notes compact.
- reprint += '<li> ' + render_markdown(string) + ' </li>' + reprint += '<li> ' + render_markdown_inline(string) + ' </li>'
—
Reply to this email directly, view it on GitHub, or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
@jhunterjActual pushed 1 commit.
—
View it on GitHub or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
@jhunterjActual pushed 1 commit.
—
View it on GitHub or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
@jhunterjActual pushed 1 commit.
—
View it on GitHub or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
@jhunterjActual pushed 1 commit.
—
View it on GitHub or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
@jhunterjActual pushed 1 commit.
—
View it on GitHub or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
@jhunterjActual commented on this pull request.
In apps/gcd/templatetags/credits.py:
> + reprint_note += ('<li> ' + render_markdown(string) +
+ ' </li>')
Addressed in the applied suggestions and e0451ef. All flagged reprint-note paths now use render_markdown_inline. Six regression cases verify compact markup while preserving formatting, links, paragraph breaks, and directional filtering. The focused run passed 68 tests.
—
Reply to this email directly, view it on GitHub, or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
@jhunterjActual commented on this pull request.
In apps/gcd/templatetags/credits.py:
> + reprint_note += ('<li> ' + render_markdown(string) +
+ ' </li>')
Addressed in the applied suggestions and e0451ef. All flagged reprint-note paths now use render_markdown_inline. Six regression cases verify compact markup while preserving formatting, links, paragraph breaks, and directional filtering. The focused run passed 68 tests.
—
Reply to this email directly, view it on GitHub, or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
@jochengcd commented on this pull request.
In apps/gcd/models/reprint.py:
> @@ -115,7 +115,9 @@ def get_compare_string(self, base_issue):
esc(issue.full_name())))
if self.notes:
- reprint = '%s [%s]' % (reprint, esc(self.notes))
The notes in a reprint do not use markdown.
—
Reply to this email directly, view it on GitHub, or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
@jochengcd commented on this pull request.
> @@ -122,12 +124,14 @@ def character_notes(character):
note = ' (%s)' % note
if character.role:
- note += ' (%s)' % character.role
+ note += ' (%s)' % (esc(character.role) if html else character.role)
Same here, short notes do not use markdown. Only the fields on the model.
—
Reply to this email directly, view it on GitHub, or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
@jochengcd commented on this pull request.
> @@ -39,8 +40,8 @@ def __init__(self, *args, **kwargs):
super(RuntimeAddSeriesRevisionForm, self).__init__(*args,
**kwargs)
self.fields['is_singleton'].help_text += \
- ' Series notes for an added singleton series will be '\
Two space indentation is correct here. We use four for a logical new line, two for line breaks.
—
Reply to this email directly, view it on GitHub, or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
@jhunterjActual commented on this pull request.
In apps/gcd/models/reprint.py:
> @@ -115,7 +115,9 @@ def get_compare_string(self, base_issue):
esc(issue.full_name())))
if self.notes:
- reprint = '%s [%s]' % (reprint, esc(self.notes))
People are currently using the Notes markdown and gcd links in Notes fields where they aren't supported, which makes them display the "raw" markdown and link coding. This was to standardize Notes fields.
—
Reply to this email directly, view it on GitHub, or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
@jochengcd commented on this pull request.
In apps/gcd/models/reprint.py:
> @@ -115,7 +115,9 @@ def get_compare_string(self, base_issue):
esc(issue.full_name())))
if self.notes:
- reprint = '%s [%s]' % (reprint, esc(self.notes))
I get that.
But these other notes fields are intended to be short and inline.
The example is an unneeded note. In which issue someone joins a group should come from the database (which can be automated), but not a note.
—
Reply to this email directly, view it on GitHub, or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
@jhunterjActual pushed 1 commit.
—
View it on GitHub or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
@jhunterjActual commented on this pull request.
> @@ -39,8 +40,8 @@ def __init__(self, *args, **kwargs):
super(RuntimeAddSeriesRevisionForm, self).__init__(*args,
**kwargs)
self.fields['is_singleton'].help_text += \
- ' Series notes for an added singleton series will be '\
Returned to the standard
—
Reply to this email directly, view it on GitHub, or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
@jhunterjActual commented on this pull request.
> @@ -122,12 +124,14 @@ def character_notes(character):
note = ' (%s)' % note
if character.role:
- note += ' (%s)' % character.role
+ note += ' (%s)' % (esc(character.role) if html else character.role)
Fixed
—
Reply to this email directly, view it on GitHub, or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
@jhunterjActual commented on this pull request.
In apps/gcd/models/reprint.py:
> @@ -115,7 +115,9 @@ def get_compare_string(self, base_issue):
esc(issue.full_name())))
if self.notes:
- reprint = '%s [%s]' % (reprint, esc(self.notes))
I see it now. Fixed.
—
Reply to this email directly, view it on GitHub, or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
Can you please explain and document what the sanitization is doing ?
—
Reply to this email directly, view it on GitHub, or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
@jhunterjActual pushed 1 commit.
—
View it on GitHub or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
Can you please explain and document what the sanitization is doing ?
Added with 5cd736b
—
Reply to this email directly, view it on GitHub, or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()