web: issue, MR and release bodies render as markdown only #51

closed cmc opened this on 2026-08-29 01:43 UTC

Discussion

cmc 2026-08-29 01:43 UTC

User-authored bodies are rendered as markdown regardless of what they contain, so org syntax shows up as literal text. Noticed on krz/org-swift!1, whose description was written in org and displays as * Why rather than a heading.

This is awkward for an org-first forge: the wiki is org, this repo's README is org, and most repos here are too. The one place a contributor writes prose in the web UI is the one place org does not work.

Where

internal/httpd/web.go: ugcFor (1052) calls mdHTML (983), which is goldmark with GFM. Three call sites, covering everything user-authored:

  • releases (554) — release notes
  • issue (1389) — issue bodies and comments
  • mr (1483) — MR descriptions and comments

Prior art in tree

aboutHTML (997) already solves this shape for profile about text: a stored format field picks a synthetic filename (about.md / about.org) and renderReadme dispatches on the extension. The org capability is already there — go-org, used for READMEs and wiki pages. This is routing, not new rendering.

What is missing is somewhere to record the format. There is no body_format on issues, MRs, comments or releases, so it needs a store migration, a way to set it over SSH (issue create --format org, and the same on edit/comment), and the render swap. Defaulting to markdown keeps every existing body rendering as it does now.

Prerequisite: do not widen the go-org include hole first

Org rendering currently only touches repository content — READMEs and wiki pages — which requires push access. Issue and MR bodies can be written by anyone who can comment.

renderReadme leaves go-org's Configuration.ReadFile at its default, so #+INCLUDE: "/etc/passwd" example reads a server file into the rendered page, and #+SETUPFILE: does the same at parse time. Routing untrusted bodies through that turns a push-gated exposure into an open one. Override ReadFile with a deny or a sandboxed reader before this lands, not after. Ref #28.

Other surfaces

krz/gitbay-ios renders these same bodies through its markdown view, so it needs the format too once the API carries it. The Parity page describes org rendering per surface and would need updating in the same MR.

referenced in commit b8cda1cc1e by cmc: org: refuse #+INCLUDE and #+SETUPFILE when rendering

2026-08-29 02:00 UTC

closed by commit d4aaf96d88 by cmc: bodies: choose markdown or org per body

2026-08-30 01:42 UTC