fix: remove SanitizeForDisplay from chunk handler responses

CleanMarkdown regex patterns (script, onclick=, javascript:, etc.)
unconditionally delete matching substrings from chunk content, even when
they appear in code blocks or inline code.

JSON APIs should return raw stored data; XSS protection is the frontend
markdown renderer's responsibility.

SanitizeForDisplay and CleanMarkdown are retained in security.go.
This commit is contained in:
MidoriKurage
2026-07-28 18:18:56 +08:00
committed by lyingbug
parent ffff3fe181
commit 002434bbb3
2 changed files with 0 additions and 15 deletions
-12
View File
@@ -75,11 +75,6 @@ func (h *ChunkHandler) GetChunkByIDOnly(c *gin.Context) {
return
}
// 对 chunk 内容进行安全清理
if chunk.Content != "" {
chunk.Content = secutils.SanitizeForDisplay(chunk.Content)
}
c.JSON(http.StatusOK, gin.H{
"success": true,
"data": chunk,
@@ -146,13 +141,6 @@ func (h *ChunkHandler) ListKnowledgeChunks(c *gin.Context) {
return
}
// 对 chunk 内容进行安全清理
for _, chunk := range result.Data.([]*types.Chunk) {
if chunk.Content != "" {
chunk.Content = secutils.SanitizeForDisplay(chunk.Content)
}
}
c.JSON(http.StatusOK, gin.H{
"success": true,
"data": result.Data,
-3
View File
@@ -366,9 +366,6 @@ func (h *EmbedChannelHandler) GetEmbedChunk(c *gin.Context) {
}
return
}
if chunk.Content != "" {
chunk.Content = secutils.SanitizeForDisplay(chunk.Content)
}
c.JSON(http.StatusOK, gin.H{"success": true, "data": chunk})
}