feat(ui.client): add plans page with markdown rendering

- Add PlansPage component with DOMPurify-sanitized markdown rendering
- Add AbortController to prevent race conditions on fast switching
- Memoize marked.parse output
- Add key={env} to PlansPage for env-consistent remount
- Encode filename in API request to handle special chars
- Fix backend: fileURLToPath instead of import.meta.dirname
- Fix backend: try/catch on readdir, remove redundant stat calls
- Fix backend: block backslash path traversal
This commit is contained in:
kislovdm
2026-07-08 18:28:43 +03:00
parent 8f0f0cd36e
commit 51e3f3776a
6 changed files with 189 additions and 52 deletions
+1 -1
View File
@@ -102,5 +102,5 @@ export async function getPlansList(): Promise<{ name: string; path: string; size
}
export async function getPlanContent(filename: string): Promise<{ name: string; content: string }> {
return request(`/api/plans/${filename}`)
return request(`/api/plans/${encodeURIComponent(filename)}`)
}