User-authored bodies are rendered as markdown regardless of what they contain, so
org syntax shows up as literal text. Noticed on krz/org-swift!1, whose description
was written in org and displays as * Why rather than a heading.
This is awkward for an org-first forge: the wiki is org, this repo's README is org, and most repos here are too. The one place a contributor writes prose in the web UI is the one place org does not work.
Where
internal/httpd/web.go: ugcFor (1052) calls mdHTML (983), which is goldmark with
GFM. Three call sites, covering everything user-authored:
releases(554) — release notesissue(1389) — issue bodies and commentsmr(1483) — MR descriptions and comments
Prior art in tree
aboutHTML (997) already solves this shape for profile about text: a stored format
field picks a synthetic filename (about.md / about.org) and renderReadme
dispatches on the extension. The org capability is already there — go-org, used for
READMEs and wiki pages. This is routing, not new rendering.
What is missing is somewhere to record the format. There is no body_format on
issues, MRs, comments or releases, so it needs a store migration, a way to set it
over SSH (issue create --format org, and the same on edit/comment), and the render
swap. Defaulting to markdown keeps every existing body rendering as it does now.
Prerequisite: do not widen the go-org include hole first
Org rendering currently only touches repository content — READMEs and wiki pages — which requires push access. Issue and MR bodies can be written by anyone who can comment.
renderReadme leaves go-org's Configuration.ReadFile at its default, so
#+INCLUDE: "/etc/passwd" example reads a server file into the rendered page, and
#+SETUPFILE: does the same at parse time. Routing untrusted bodies through that
turns a push-gated exposure into an open one. Override ReadFile with a deny or a
sandboxed reader before this lands, not after. Ref #28.
Other surfaces
krz/gitbay-ios renders these same bodies through its markdown view, so it needs the format too once the API carries it. The Parity page describes org rendering per surface and would need updating in the same MR.
referenced in commit b8cda1cc1e by cmc: org: refuse #+INCLUDE and #+SETUPFILE when rendering
2026-08-29 02:00 UTC