Class MarkdownRenderer

java.lang.Object
io.jenkins.plugins.interactiveinput.util.MarkdownRenderer

public final class MarkdownRenderer extends Object
Safe markdown-to-HTML rendering for the modal's context panel and free-text preview (ยง7.5).

Uses commonmark-java configured to escape raw HTML and sanitise URLs, so user-supplied markdown (contextMarkdown and free text) can never inject script or raw HTML into the DOM. This replaces the spec's suggested (and nonexistent) StrictEscapesExtension with the library's supported escapeHtml/sanitizeUrls switches โ€” see SESSION_NOTES.

GitHub-Flavored Markdown extensions (tables, strikethrough, autolinks) are enabled on top of the CommonMark core โ€” those constructs are not in the core spec, so without the extensions a pipe table renders as a literal "|"-delimited paragraph (the Interactive View table bug). See EXTENSIONS. The extensions ship with the markdown-formatter plugin dependency, so no additional jar is bundled, and escaping / URL sanitisation still apply to their output.

  • Method Details

    • render

      @NonNull public static String render(@CheckForNull String markdown)
      Parameters:
      markdown - raw markdown (may be null)
      Returns:
      sanitised HTML safe to insert into the DOM; empty string for null/blank input
    • renderWithSourceLines

      @NonNull public static String renderWithSourceLines(@CheckForNull String markdown)
      Same safe rendering as render(String), but additionally tags each top-level block element with data-source-line="<n>" (1-based line in the markdown source).

      Used only for the Interactive View document body so a reviewer can attach inline comments to a rendered block and have them map to the same source line as the Source view (and vice-versa). Escaping and URL sanitisation are identical to render(String) โ€” the attribute provider only adds a numeric line hint, never markup or user text.

      Parameters:
      markdown - raw markdown (may be null)
      Returns:
      sanitised HTML with source-line anchors; empty string for null/blank input