From ddb310ed15fcd693a5487e5f38b5ba74cdf27843 Mon Sep 17 00:00:00 2001 From: Christian Cleberg Date: Mon, 30 Mar 2026 16:22:59 -0500 Subject: Migrate README markdown rendering to swift-markdown and fix badge images - replace the hand-rolled markdown parser with a MarkupVisitor renderer - keep the org-mode rendering path and shared sanitization helpers intact - update WKWebView styling and height measurement for README content - fix linked image and query-string badge rendering in markdown output - expand README rendering tests and add markdown syntax coverage Implements: https://todo.sr.ht/~ccleberg/Hutch/2 --- Hutch.xcodeproj/project.pbxproj | 29 ++ .../xcshareddata/swiftpm/Package.resolved | 24 ++ .../Views/Repositories/MarkdownHTMLRenderer.swift | 206 +++++++++++ Hutch/Views/Repositories/ReadmeView.swift | 378 +++------------------ HutchTests/ReadmeViewTests.swift | 107 +++--- 5 files changed, 358 insertions(+), 386 deletions(-) create mode 100644 Hutch.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved create mode 100644 Hutch/Views/Repositories/MarkdownHTMLRenderer.swift diff --git a/Hutch.xcodeproj/project.pbxproj b/Hutch.xcodeproj/project.pbxproj index a52d824..e72dfd4 100644 --- a/Hutch.xcodeproj/project.pbxproj +++ b/Hutch.xcodeproj/project.pbxproj @@ -11,6 +11,8 @@ 8B2F89672F69DEB900FC0253 /* README.md in Resources */ = {isa = PBXBuildFile; fileRef = 8B2F89642F69DEB900FC0253 /* README.md */; }; 8B2F89682F69DEB900FC0253 /* SECURITY.md in Resources */ = {isa = PBXBuildFile; fileRef = 8B2F89652F69DEB900FC0253 /* SECURITY.md */; }; 8BE082012F80000100000001 /* HutchWidgetExtension.appex in Embed App Extensions */ = {isa = PBXBuildFile; fileRef = 8BE081F62F80000100000001 /* HutchWidgetExtension.appex */; settings = {ATTRIBUTES = (RemoveHeadersOnCopy, ); }; }; + 8BE09E792F7B20CB00F88693 /* TEST_README.md in Resources */ = {isa = PBXBuildFile; fileRef = 8BE09E782F7B20CB00F88693 /* TEST_README.md */; }; + 8BF100032F9A000100000001 /* Markdown in Frameworks */ = {isa = PBXBuildFile; productRef = 8BF100022F9A000100000001 /* Markdown */; }; /* End PBXBuildFile section */ /* Begin PBXContainerItemProxy section */ @@ -53,6 +55,7 @@ 8B8182C22F6B742B000AE049 /* HutchTests */ = {isa = PBXFileReference; lastKnownFileType = folder; path = HutchTests; sourceTree = ""; }; 8BDCA5272F6B76B20066AA29 /* HutchTests.xctestplan */ = {isa = PBXFileReference; lastKnownFileType = text; path = HutchTests.xctestplan; sourceTree = ""; }; 8BE081F62F80000100000001 /* HutchWidgetExtension.appex */ = {isa = PBXFileReference; explicitFileType = "wrapper.app-extension"; includeInIndex = 0; path = HutchWidgetExtension.appex; sourceTree = BUILT_PRODUCTS_DIR; }; + 8BE09E782F7B20CB00F88693 /* TEST_README.md */ = {isa = PBXFileReference; lastKnownFileType = net.daringfireball.markdown; path = TEST_README.md; sourceTree = ""; }; /* End PBXFileReference section */ /* Begin PBXFileSystemSynchronizedBuildFileExceptionSet section */ @@ -106,6 +109,7 @@ isa = PBXFrameworksBuildPhase; buildActionMask = 2147483647; files = ( + 8BF100032F9A000100000001 /* Markdown in Frameworks */, ); runOnlyForDeploymentPostprocessing = 0; }; @@ -139,6 +143,7 @@ 8BE081F52F80000100000001 /* HutchWidgetExtension */, 8B8182B82F6B73F3000AE049 /* HutchTests */, 8B4B28D22F6704280045FA19 /* Products */, + 8BE09E782F7B20CB00F88693 /* TEST_README.md */, ); sourceTree = ""; }; @@ -175,6 +180,7 @@ ); name = Hutch; packageProductDependencies = ( + 8BF100022F9A000100000001 /* Markdown */, ); productName = Hutch; productReference = 8B4B28D12F6704280045FA19 /* Hutch.app */; @@ -254,6 +260,9 @@ ); mainGroup = 8B4B28C82F6704280045FA19; minimizedProjectReferenceProxies = 1; + packageReferences = ( + 8BF100012F9A000100000001 /* XCRemoteSwiftPackageReference "swift-markdown" */, + ); preferredProjectObjectVersion = 77; productRefGroup = 8B4B28D22F6704280045FA19 /* Products */; projectDirPath = ""; @@ -272,6 +281,7 @@ buildActionMask = 2147483647; files = ( 8B2F89662F69DEB900FC0253 /* LICENSE in Resources */, + 8BE09E792F7B20CB00F88693 /* TEST_README.md in Resources */, 8B2F89672F69DEB900FC0253 /* README.md in Resources */, 8B2F89682F69DEB900FC0253 /* SECURITY.md in Resources */, ); @@ -668,6 +678,25 @@ defaultConfigurationName = Release; }; /* End XCConfigurationList section */ + +/* Begin XCRemoteSwiftPackageReference section */ + 8BF100012F9A000100000001 /* XCRemoteSwiftPackageReference "swift-markdown" */ = { + isa = XCRemoteSwiftPackageReference; + repositoryURL = "https://github.com/apple/swift-markdown"; + requirement = { + kind = upToNextMajorVersion; + minimumVersion = 0.7.3; + }; + }; +/* End XCRemoteSwiftPackageReference section */ + +/* Begin XCSwiftPackageProductDependency section */ + 8BF100022F9A000100000001 /* Markdown */ = { + isa = XCSwiftPackageProductDependency; + package = 8BF100012F9A000100000001 /* XCRemoteSwiftPackageReference "swift-markdown" */; + productName = Markdown; + }; +/* End XCSwiftPackageProductDependency section */ }; rootObject = 8B4B28C92F6704280045FA19 /* Project object */; } diff --git a/Hutch.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved b/Hutch.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved new file mode 100644 index 0000000..a2a45a3 --- /dev/null +++ b/Hutch.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved @@ -0,0 +1,24 @@ +{ + "originHash" : "b809819531d430dc5b7a0fb1fb5538d0321c5d541eed52a9990f37c38dd0f98a", + "pins" : [ + { + "identity" : "swift-cmark", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-cmark.git", + "state" : { + "revision" : "5d9bdaa4228b381639fff09403e39a04926e2dbe", + "version" : "0.7.1" + } + }, + { + "identity" : "swift-markdown", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-markdown", + "state" : { + "revision" : "7d9a5ce307528578dfa777d505496bd5f544ad94", + "version" : "0.7.3" + } + } + ], + "version" : 3 +} diff --git a/Hutch/Views/Repositories/MarkdownHTMLRenderer.swift b/Hutch/Views/Repositories/MarkdownHTMLRenderer.swift new file mode 100644 index 0000000..67966f1 --- /dev/null +++ b/Hutch/Views/Repositories/MarkdownHTMLRenderer.swift @@ -0,0 +1,206 @@ +import Markdown + +nonisolated func markdownToHTML(_ text: String, imageURLResolver: ((String) -> String?)? = nil) -> String { + let document = Document(parsing: text) + var renderer = MarkdownHTMLRenderer(imageURLResolver: imageURLResolver) + return renderer.visit(document) +} + +private struct MarkdownHTMLRenderer: MarkupVisitor { + typealias Result = String + + nonisolated(unsafe) let imageURLResolver: ((String) -> String?)? + private var isRenderingTableHead = false + + nonisolated init(imageURLResolver: ((String) -> String?)?) { + self.imageURLResolver = imageURLResolver + } + + nonisolated mutating func visit(_ markup: Markup) -> String { + markup.accept(&self) + } + + nonisolated mutating func defaultVisit(_ markup: Markup) -> String { + visitChildren(of: markup) + } + + nonisolated mutating func visitDocument(_ document: Document) -> String { + visitChildren(of: document) + } + + nonisolated mutating func visitHeading(_ heading: Heading) -> String { + "\(visitChildren(of: heading))\n" + } + + nonisolated mutating func visitParagraph(_ paragraph: Paragraph) -> String { + "

\(visitChildren(of: paragraph))

\n" + } + + nonisolated mutating func visitBlockQuote(_ blockQuote: BlockQuote) -> String { + "
\n\(visitChildren(of: blockQuote))
\n" + } + + nonisolated mutating func visitUnorderedList(_ unorderedList: UnorderedList) -> String { + "
    \n\(visitChildren(of: unorderedList))
\n" + } + + nonisolated mutating func visitOrderedList(_ orderedList: OrderedList) -> String { + "
    \n\(visitChildren(of: orderedList))
\n" + } + + nonisolated mutating func visitListItem(_ listItem: ListItem) -> String { + if let checkbox = listItem.checkbox, + listItem.childCount == 1, + let paragraph = listItem.child(at: 0) as? Paragraph { + let content = visitChildren(of: paragraph) + return "
  • \(checkboxHTML(for: checkbox)) \(content)
  • \n" + } + + var body = visitChildren(of: listItem) + if let checkbox = listItem.checkbox { + body = "\(checkboxHTML(for: checkbox))" + body + } + return "
  • \(body)
  • \n" + } + + nonisolated mutating func visitCodeBlock(_ codeBlock: CodeBlock) -> String { + let classAttribute: String + if let language = codeBlock.language, !language.isEmpty { + classAttribute = " class=\"language-\(escapeHTMLAttribute(language))\"" + } else { + classAttribute = "" + } + return "
    \(escapeHTML(codeBlock.code))
    \n" + } + + nonisolated mutating func visitInlineCode(_ inlineCode: InlineCode) -> String { + "\(escapeHTML(inlineCode.code))" + } + + nonisolated mutating func visitThematicBreak(_: ThematicBreak) -> String { + "
    \n" + } + + nonisolated mutating func visitHTMLBlock(_ html: HTMLBlock) -> String { + guard let sanitized = sanitizedMarkdownHTMLBlock(html.rawHTML) else { return "" } + return sanitized + "\n" + } + + nonisolated mutating func visitInlineHTML(_ inlineHTML: InlineHTML) -> String { + sanitizedMarkdownHTMLTag(inlineHTML.rawHTML) ?? "" + } + + nonisolated mutating func visitLink(_ link: Markdown.Link) -> String { + let content = visitChildren(of: link) + guard let destination = link.destination, + let sanitizedDestination = sanitizedReadmeLinkURLString(destination) else { + return content + } + let href = escapeHTMLAttribute(decodeHTMLEntities(sanitizedDestination)) + return "\(content)" + } + + nonisolated mutating func visitImage(_ image: Markdown.Image) -> String { + let altText = plainText(from: image) + guard let source = image.source, !source.isEmpty else { + return escapeHTML(altText) + } + + let resolvedSource = imageURLResolver?(source) ?? source + guard let sanitizedSource = sanitizedReadmeImageURLString(resolvedSource) else { + return escapeHTML(altText) + } + + let src = escapeHTMLAttribute(decodeHTMLEntities(sanitizedSource)) + return "\"\(escapeHTMLAttribute(altText))\"" + } + + nonisolated mutating func visitStrong(_ strong: Strong) -> String { + "\(visitChildren(of: strong))" + } + + nonisolated mutating func visitEmphasis(_ emphasis: Emphasis) -> String { + "\(visitChildren(of: emphasis))" + } + + nonisolated mutating func visitStrikethrough(_ strikethrough: Strikethrough) -> String { + "\(visitChildren(of: strikethrough))" + } + + nonisolated mutating func visitText(_ text: Markdown.Text) -> String { + escapeHTML(text.string) + } + + nonisolated mutating func visitSoftBreak(_: SoftBreak) -> String { + " " + } + + nonisolated mutating func visitLineBreak(_: LineBreak) -> String { + "
    " + } + + nonisolated mutating func visitTable(_ table: Markdown.Table) -> String { + "\n\(visitChildren(of: table))
    \n" + } + + nonisolated mutating func visitTableHead(_ tableHead: Markdown.Table.Head) -> String { + let previousValue = isRenderingTableHead + isRenderingTableHead = true + let content = visitChildren(of: tableHead) + isRenderingTableHead = previousValue + return "\(content)\n" + } + + nonisolated mutating func visitTableBody(_ tableBody: Markdown.Table.Body) -> String { + let previousValue = isRenderingTableHead + isRenderingTableHead = false + let content = visitChildren(of: tableBody) + isRenderingTableHead = previousValue + return "\n\(content)\n" + } + + nonisolated mutating func visitTableRow(_ tableRow: Markdown.Table.Row) -> String { + "\(visitChildren(of: tableRow))\n" + } + + nonisolated mutating func visitTableCell(_ tableCell: Markdown.Table.Cell) -> String { + let tagName = isRenderingTableHead ? "th" : "td" + return "<\(tagName)>\(visitChildren(of: tableCell))" + } + + nonisolated private mutating func visitChildren(of markup: Markup) -> String { + var html = "" + for child in markup.children { + html += visit(child) + } + return html + } + + nonisolated private func plainText(from markup: Markup) -> String { + switch markup { + case let text as Markdown.Text: + return text.string + case let inlineCode as InlineCode: + return inlineCode.code + case is SoftBreak: + return " " + case is LineBreak: + return "\n" + default: + var text = "" + for child in markup.children { + text += plainText(from: child) + } + return text + } + } + + nonisolated private func checkboxHTML(for checkbox: Checkbox) -> String { + switch checkbox { + case .checked: + return "" + case .unchecked: + return "" + } + } +} diff --git a/Hutch/Views/Repositories/ReadmeView.swift b/Hutch/Views/Repositories/ReadmeView.swift index 27cec55..10caeed 100644 --- a/Hutch/Views/Repositories/ReadmeView.swift +++ b/Hutch/Views/Repositories/ReadmeView.swift @@ -276,309 +276,8 @@ func clearWebContentRenderCaches() { // MARK: - Markdown to HTML -nonisolated func markdownToHTML(_ text: String, imageURLResolver: ((String) -> String?)? = nil) -> String { - let normalizedText = text - .replacingOccurrences(of: "\r\n", with: "\n") - .replacingOccurrences(of: "\r", with: "\n") - let lines = normalizedText.split(separator: "\n", omittingEmptySubsequences: false).map(String.init) - var html = "" - var inCodeBlock = false - var codeBlockInListItem = false - var codeBlockLines: [String] = [] - var listType: MarkupListType? - var inBlockquote = false - var pendingListItemBreak = false - var currentListItemLines: [String] = [] - var currentListItemBlocks: [String] = [] - var paragraph: [String] = [] - var tableRows: [[String]] = [] - - func flushParagraph() { - if !paragraph.isEmpty { - let normalizedParagraph = paragraph - .map { $0.trimmingCharacters(in: .whitespaces) } - .joined(separator: " ") - html += "

    " + normalizedParagraph + "

    \n" - paragraph = [] - } - } - - func flushListItem() { - guard !currentListItemLines.isEmpty || !currentListItemBlocks.isEmpty else { return } - let itemContent = currentListItemLines - .map { $0.trimmingCharacters(in: .whitespaces) } - .joined(separator: " ") - - if currentListItemBlocks.isEmpty { - html += "
  • " + renderTaskListItem( - itemContent, - inlineRenderer: { processInline($0, imageURLResolver: imageURLResolver) } - ) + "
  • \n" - } else { - if !itemContent.isEmpty { - currentListItemBlocks.append( - "

    " + renderTaskListItem( - itemContent, - inlineRenderer: { processInline($0, imageURLResolver: imageURLResolver) } - ) + "

    " - ) - } - html += "
  • " + currentListItemBlocks.joined(separator: "\n") + "
  • \n" - } - currentListItemLines = [] - currentListItemBlocks = [] - } - - func flushListItemParagraphIntoBlocks() { - guard !currentListItemLines.isEmpty else { return } - let itemContent = currentListItemLines - .map { $0.trimmingCharacters(in: .whitespaces) } - .joined(separator: " ") - currentListItemBlocks.append( - "

    " + renderTaskListItem( - itemContent, - inlineRenderer: { processInline($0, imageURLResolver: imageURLResolver) } - ) + "

    " - ) - currentListItemLines = [] - } - - func flushCodeBlock() { - let content = codeBlockLines.joined(separator: "\n") - let blockHTML = "
    " + content + "
    \n" - if codeBlockInListItem { - currentListItemBlocks.append(blockHTML) - } else { - html += blockHTML - } - codeBlockLines = [] - codeBlockInListItem = false - } - - func closeList() { - flushListItem() - switch listType { - case .unordered: - html += "\n" - case .ordered: - html += "\n" - case nil: - break - } - listType = nil - } - - func flushTable() { - guard !tableRows.isEmpty else { return } - html += renderHTMLTable( - rows: tableRows, - inlineRenderer: { processInline($0, imageURLResolver: imageURLResolver) } - ) - tableRows = [] - } - - func closeBlockquote() { - if inBlockquote { - flushParagraph() - html += "\n" - inBlockquote = false - } - } - - for line in lines { - let trimmed = line.trimmingCharacters(in: .whitespaces) - - if pendingListItemBreak, listType != nil { - if trimmed.isEmpty { - continue - } - if isIndentedContinuationLine(line) || trimmed.hasPrefix("```") { - pendingListItemBreak = false - } else if isMarkdownUnorderedListItem(trimmed) || orderedListItem(in: trimmed) != nil { - flushListItem() - pendingListItemBreak = false - } else { - flushListItem() - closeList() - pendingListItemBreak = false - } - } - - if let rawHTML = sanitizedMarkdownHTMLLine(from: trimmed) { - closeBlockquote() - flushParagraph() - flushTable() - if listType != nil { - flushListItemParagraphIntoBlocks() - currentListItemBlocks.append(rawHTML) - } else { - closeList() - html += rawHTML + "\n" - } - continue - } - - // Fenced code blocks - if trimmed.hasPrefix("```") { - if inCodeBlock { - flushCodeBlock() - inCodeBlock = false - } else { - closeBlockquote() - flushParagraph() - flushTable() - codeBlockInListItem = listType != nil && (!currentListItemLines.isEmpty || !currentListItemBlocks.isEmpty) - if !codeBlockInListItem { - closeList() - } else { - flushListItemParagraphIntoBlocks() - } - inCodeBlock = true - codeBlockLines = [] - } - continue - } - - if inCodeBlock { - codeBlockLines.append(escapeHTML(line)) - continue - } - - if isTableLine(trimmed) { - closeBlockquote() - flushParagraph() - closeList() - tableRows.append(parseTableRow(trimmed)) - continue - } else { - flushTable() - } - - // Headings - if line.hasPrefix("###### ") { - closeBlockquote() - flushParagraph() - closeList() - html += "
    " + processInline(String(line.dropFirst(7)), imageURLResolver: imageURLResolver) + "
    \n" - continue - } - if line.hasPrefix("##### ") { - closeBlockquote() - flushParagraph() - closeList() - html += "
    " + processInline(String(line.dropFirst(6)), imageURLResolver: imageURLResolver) + "
    \n" - continue - } - if line.hasPrefix("#### ") { - closeBlockquote() - flushParagraph() - closeList() - html += "

    " + processInline(String(line.dropFirst(5)), imageURLResolver: imageURLResolver) + "

    \n" - continue - } - if line.hasPrefix("### ") { - closeBlockquote() - flushParagraph() - closeList() - html += "

    " + processInline(String(line.dropFirst(4)), imageURLResolver: imageURLResolver) + "

    \n" - continue - } - if line.hasPrefix("## ") { - closeBlockquote() - flushParagraph() - closeList() - html += "

    " + processInline(String(line.dropFirst(3)), imageURLResolver: imageURLResolver) + "

    \n" - continue - } - if line.hasPrefix("# ") { - closeBlockquote() - flushParagraph() - closeList() - html += "

    " + processInline(String(line.dropFirst(2)), imageURLResolver: imageURLResolver) + "

    \n" - continue - } - - if isMarkdownHorizontalRule(trimmed) { - closeBlockquote() - flushParagraph() - closeList() - html += "
    \n" - continue - } - - if trimmed.hasPrefix("> ") { - flushTable() - closeList() - if !inBlockquote { - flushParagraph() - html += "
    \n" - inBlockquote = true - } - paragraph.append(processInline(String(trimmed.dropFirst(2)), imageURLResolver: imageURLResolver)) - continue - } else { - closeBlockquote() - } - - // List items - if trimmed.hasPrefix("- ") || trimmed.hasPrefix("* ") { - flushParagraph() - if listType != .unordered { - closeList() - html += "
      \n" - listType = .unordered - } - flushListItem() - currentListItemLines = [String(trimmed.dropFirst(2))] - continue - } - if let orderedItem = orderedListItem(in: trimmed) { - flushParagraph() - if listType != .ordered { - closeList() - html += "
        \n" - listType = .ordered - } - flushListItem() - currentListItemLines = [orderedItem] - continue - } - - if listType != nil && isIndentedContinuationLine(line) { - currentListItemLines.append(trimmed) - continue - } - - // Blank line - if trimmed.isEmpty { - if inBlockquote { - closeBlockquote() - } else if listType != nil, !currentListItemLines.isEmpty || !currentListItemBlocks.isEmpty { - pendingListItemBreak = true - } else { - flushParagraph() - closeList() - } - continue - } - - // Regular text — accumulate into paragraph - paragraph.append(processInline(line, imageURLResolver: imageURLResolver)) - } - - // Flush remaining state - if inCodeBlock { - flushCodeBlock() - } - closeBlockquote() - flushParagraph() - flushTable() - closeList() - - return html -} - nonisolated func processInline(_ text: String, imageURLResolver: ((String) -> String?)? = nil) -> String { + var protectedFragments: [String: String] = [:] var result = protectMatches( in: text, @@ -1109,7 +808,7 @@ nonisolated func escapeHTML(_ text: String) -> String { .replacingOccurrences(of: "\"", with: """) } -nonisolated private func escapeHTMLAttribute(_ text: String) -> String { +nonisolated func escapeHTMLAttribute(_ text: String) -> String { escapeHTML(text).replacingOccurrences(of: "'", with: "'") } @@ -1212,21 +911,16 @@ nonisolated private func renderHTMLTable( return html } -private enum MarkupListType: Equatable { +private enum OrgListType: Equatable { case unordered case ordered } -private typealias OrgListType = MarkupListType - nonisolated private func orderedListItem(in line: String) -> String? { guard let match = line.firstMatch(of: /^(\d+)\.\s+(.+)$/) else { return nil } return String(match.2) } -nonisolated private func isMarkdownHorizontalRule(_ line: String) -> Bool { - matchesRegex(line, pattern: #"^\s*([*\-_])(?:\s*\1){2,}\s*$"#) -} nonisolated private func isOrgHorizontalRule(_ line: String) -> Bool { matchesRegex(line, pattern: #"^\s*-{5,}\s*$"#) @@ -1252,11 +946,8 @@ nonisolated private func isIndentedContinuationLine(_ line: String) -> Bool { return first == " " || first == "\t" } -nonisolated private func isMarkdownUnorderedListItem(_ line: String) -> Bool { - line.hasPrefix("- ") || line.hasPrefix("* ") -} -nonisolated private func decodeHTMLEntities(_ text: String) -> String { +nonisolated func decodeHTMLEntities(_ text: String) -> String { text .replacingOccurrences(of: "&", with: "&") .replacingOccurrences(of: """, with: "\"") @@ -1265,12 +956,34 @@ nonisolated private func decodeHTMLEntities(_ text: String) -> String { .replacingOccurrences(of: ">", with: ">") } -nonisolated private func sanitizedMarkdownHTMLLine(from line: String) -> String? { - guard line.hasPrefix("<"), line.hasSuffix(">") else { return nil } - return sanitizedMarkdownHTMLTag(line) +nonisolated func sanitizedMarkdownHTMLBlock(_ rawHTML: String) -> String? { + var protectedFragments: [String: String] = [:] + var foundUnsafeMarkup = false + let protected = protectMatches( + in: rawHTML, + pattern: #"(?s)|]*?>"#, + protectedFragments: &protectedFragments + ) { match, nsText in + let rawTag = nsText.substring(with: match.range) + guard let sanitizedTag = sanitizedMarkdownHTMLTag(rawTag) else { + foundUnsafeMarkup = true + return "" + } + return sanitizedTag + } + + guard !foundUnsafeMarkup else { return nil } + + var sanitized = escapeHTML(protected) + sanitized = replaceMatches(in: sanitized, pattern: #"ZZPROTECTED\d+ZZ"#) { match, nsText in + let token = nsText.substring(with: match.range) + return protectedFragments[token] ?? "" + } + + return sanitized.trimmingCharacters(in: .whitespacesAndNewlines).isEmpty ? nil : sanitized } -nonisolated private func sanitizedMarkdownHTMLTag(_ rawTag: String) -> String? { +nonisolated func sanitizedMarkdownHTMLTag(_ rawTag: String) -> String? { let trimmed = rawTag.trimmingCharacters(in: .whitespacesAndNewlines) guard trimmed.hasPrefix("<"), trimmed.hasSuffix(">") else { return nil } guard !trimmed.lowercased().hasPrefix("