feat(ui.client): add plans page with markdown rendering
- Add PlansPage component with DOMPurify-sanitized markdown rendering
- Add AbortController to prevent race conditions on fast switching
- Memoize marked.parse output
- Add key={env} to PlansPage for env-consistent remount
- Encode filename in API request to handle special chars
- Fix backend: fileURLToPath instead of import.meta.dirname
- Fix backend: try/catch on readdir, remove redundant stat calls
- Fix backend: block backslash path traversal
This commit is contained in:
@@ -102,5 +102,5 @@ export async function getPlansList(): Promise<{ name: string; path: string; size
|
||||
}
|
||||
|
||||
export async function getPlanContent(filename: string): Promise<{ name: string; content: string }> {
|
||||
return request(`/api/plans/${filename}`)
|
||||
return request(`/api/plans/${encodeURIComponent(filename)}`)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user