fc6f15534ed0a09ccddd7dac42f558dd6578ec59
The edit textarea was running `data.orig` through the browser's HTML parser via a detached `<span>.innerHTML` to "decode entities", which turned user-typed `<`/`>` into real `<`/`>`. On save, blackfriday then saw a real `<script>` tag, bluemonday stripped it, and the comment body collapsed to an empty string. The decode block predates commit243c835(2022) which stopped the backend from sanitising `orig` with bluemonday. Before243c835, orig came back HTML-escaped from the API and the frontend compensated. After243c835the backend stores and returns orig byte-for-byte, but the frontend decode was never removed — so it has been silently corrupting user input containing entities for ~3.5 years. The backend contract is clear: `orig` is the raw user input, never rendered as HTML. The frontend should echo it back into the textarea unchanged. This change removes the decode and adds 45 table-driven regression tests covering entity round-trips, unicode edge cases, and markdown constructs.
Remark42

Remark42 is a self-hosted, lightweight and simple (yet functional) comment engine, which doesn't spy on users. It can be embedded into blogs, articles, or any other place where readers add comments.
- Social login via Google, Facebook, Microsoft, GitHub, Apple, Yandex, Patreon, Discord and Telegram
- Login via email
- Optional anonymous access
- Multi-level nested comments with both tree and plain presentations
- Import from Disqus and WordPress
- Markdown support with friendly formatter toolbar
- Moderator can remove comments and block users
- Voting, pinning and verification system
- Sortable comments
- Images upload with drag-and-drop
- Extractor for recent comments, cross-post
- RSS for all comments and each post
- Telegram, Slack, Webhook and email notifications for Admins (get notified for each new comment)
- Email and Telegram notifications for users (get notified when someone responds to your comment)
- Export data to JSON with automatic backups
- No external databases, everything embedded in a single data file
- Fully dockerized and can be deployed in a single command
- Self-contained executable can be deployed directly to Linux, Windows and macOS
- Clean, lightweight and customizable UI with white and dark themes
- Multi-site mode from a single instance
- Integration with automatic SSL (direct and via nginx-le)
- Privacy focused
Demo site available with all authentication methods, including email auth and anonymous access.
All remark42 documentation is available by the link.
Contribution
In order to start and work on the project locally in development mode check our contribution documentation for backend and frontend.
If you are interested in adding a new localization please check these docs.
Related projects
Languages
Go
69.4%
TypeScript
22.8%
CSS
3.2%
HTML
1.3%
JavaScript
1.3%
Other
2%
