website/js/markdown.js

website/js/markdown.js

the website's source · 489 lines · read it on GitHub

WHAT IT DOES

A small Markdown renderer and syntax highlighter.

# Why not a library

Pulling marked and highlight.js off a CDN would be three lines. It would also mean every visitor to a privacy tool's website makes requests to a third party that learns their IP address and what they were reading, and it would mean trusting code nobody here has read. This is a few hundred lines that does what this page needs and nothing else.

# Escaping

Everything is HTML-escaped first, and only the tags this renderer itself emits are ever introduced. Raw HTML in the source Markdown is shown as text rather than injected, so the README cannot inject script into this page even if it were altered upstream.

IN PLAIN WORDS

This turns the project's plain-text documents into the formatted pages you read, including the colours in the code examples.

Most sites borrow somebody else's code from another company's server to do this. That would tell that company your address and what you were reading. This is a few hundred lines written here instead, so nothing about your visit leaves this site.

WHAT CALLS WHAT

escapeHtml line 64 parker line 95 park line 98 unpark line 119 keywordsFor line 160 highlight line 164 lang line 166 safeUrl line 225 isExternal line 231 inline line 307 render line 360 tableRow line 366 cells line 419

Read out of the source: an edge means the callee’s name appears, called, inside the caller’s body. A syntactic reading, not a resolved one.

FunctionLine
escapeHtml64
parker95
park98
unpark119
keywordsFor160
highlight164
lang166
safeUrl225
isExternal231
inline307
render360
tableRow366
cells419