Class MarkdownRenderer
Uses commonmark-java configured to escape raw HTML and sanitise URLs, so
user-supplied markdown (contextMarkdown and free text) can never inject script or raw HTML
into the DOM. This replaces the spec's suggested (and nonexistent) StrictEscapesExtension
with the library's supported escapeHtml/sanitizeUrls switches โ see SESSION_NOTES.
GitHub-Flavored Markdown extensions (tables, strikethrough, autolinks) are enabled on top of the
CommonMark core โ those constructs are not in the core spec, so without the extensions a
pipe table renders as a literal "|"-delimited paragraph (the Interactive View table bug). See
EXTENSIONS. The extensions ship with the markdown-formatter plugin dependency, so
no additional jar is bundled, and escaping / URL sanitisation still apply to their output.
-
Method Summary
Modifier and TypeMethodDescriptionstatic Stringstatic StringrenderWithSourceLines(String markdown) Same safe rendering asrender(String), but additionally tags each top-level block element withdata-source-line="<n>"(1-based line in the markdown source).
-
Method Details
-
render
- Parameters:
markdown- raw markdown (may benull)- Returns:
- sanitised HTML safe to insert into the DOM; empty string for
null/blank input
-
renderWithSourceLines
Same safe rendering asrender(String), but additionally tags each top-level block element withdata-source-line="<n>"(1-based line in the markdown source).Used only for the Interactive View document body so a reviewer can attach inline comments to a rendered block and have them map to the same source line as the Source view (and vice-versa). Escaping and URL sanitisation are identical to
render(String)โ the attribute provider only adds a numeric line hint, never markup or user text.- Parameters:
markdown- raw markdown (may benull)- Returns:
- sanitised HTML with source-line anchors; empty string for
null/blank input
-