From 002434bbb3da059d01f9c07f630dd7a17e4aee83 Mon Sep 17 00:00:00 2001 From: MidoriKurage Date: Sun, 26 Jul 2026 20:08:07 +0800 Subject: [PATCH] fix: remove SanitizeForDisplay from chunk handler responses CleanMarkdown regex patterns (script, onclick=, javascript:, etc.) unconditionally delete matching substrings from chunk content, even when they appear in code blocks or inline code. JSON APIs should return raw stored data; XSS protection is the frontend markdown renderer's responsibility. SanitizeForDisplay and CleanMarkdown are retained in security.go. --- internal/handler/chunk.go | 12 ------------ internal/handler/embed_channel.go | 3 --- 2 files changed, 15 deletions(-) diff --git a/internal/handler/chunk.go b/internal/handler/chunk.go index cfc5142a9..041bdcf1a 100644 --- a/internal/handler/chunk.go +++ b/internal/handler/chunk.go @@ -75,11 +75,6 @@ func (h *ChunkHandler) GetChunkByIDOnly(c *gin.Context) { return } - // 对 chunk 内容进行安全清理 - if chunk.Content != "" { - chunk.Content = secutils.SanitizeForDisplay(chunk.Content) - } - c.JSON(http.StatusOK, gin.H{ "success": true, "data": chunk, @@ -146,13 +141,6 @@ func (h *ChunkHandler) ListKnowledgeChunks(c *gin.Context) { return } - // 对 chunk 内容进行安全清理 - for _, chunk := range result.Data.([]*types.Chunk) { - if chunk.Content != "" { - chunk.Content = secutils.SanitizeForDisplay(chunk.Content) - } - } - c.JSON(http.StatusOK, gin.H{ "success": true, "data": result.Data, diff --git a/internal/handler/embed_channel.go b/internal/handler/embed_channel.go index 233b38b21..df60f51e4 100644 --- a/internal/handler/embed_channel.go +++ b/internal/handler/embed_channel.go @@ -366,9 +366,6 @@ func (h *EmbedChannelHandler) GetEmbedChunk(c *gin.Context) { } return } - if chunk.Content != "" { - chunk.Content = secutils.SanitizeForDisplay(chunk.Content) - } c.JSON(http.StatusOK, gin.H{"success": true, "data": chunk}) }