- Add shared BlogMD renderer (static/js/markdown.js): marked + DOMPurify
+ highlight.js pipeline with GFM support, heading id slugger with
CJK-aware anchors, syntax highlighting, per-block copy button and
language badge, lazy images with lightbox, external links opened
safely in new tabs, tables wrapped for small screens.
- Add .md-body typography styles (static/css/markdown.css) so articles,
comments and editor previews render with proper headings, tables,
lists, blockquotes and code blocks (previously the prose classes had
no effect because the Tailwind typography plugin is not loaded).
- Fix marked options that were set after parsing and removed from
marked v4+ (mangle/headerIds no-ops).
- Pin CDN versions (marked 15.0.12, dompurify 3.4.13, highlight.js
11.12.0) instead of floating 'latest' URLs.
- Wire EasyMDE preview/side-by-side to BlogMD in admin and user
article editors; use BlogMD for comment bodies on the article page,
admin comment list and comment preview.
- Serve /static in main.go and deploy it in install_linux.sh.
- Comment model with nested replies (ParentID), dual authorship
(logged-in UserID / anonymous GuestToken cookie), email hash for
Gravatar, private flag, and moderation status
- CommentConfig singleton (enabled / allow guest / guest-require-approval
/ use Gravatar) cached like the other platform config
- Markdown comments with built-in emoji picker, preview, and markdown
help; rendered client-side via marked + DOMPurify, with server-side
HTML/dangerous-scheme stripping as a first XSS defense
- Private comments visible only to admin and the author; pending
comments visible only to admin and the author
- Admin moderation list (pending/approved/rejected/all tabs) with
approve/reject/delete and a pending-count badge
- Comment settings page with the four toggles
- One-time session flash notice (auto-dismissed after 4s) so the
"comment posted" banner no longer persists across refreshes
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>