Add Markdown component with GFM support and XSS protection - #19

Merged
hotlong merged 7 commits into
mainfrom
copilot/add-markdown-component
Jan 14, 2026
Merged

Add Markdown component with GFM support and XSS protection#19
hotlong merged 7 commits into
mainfrom
copilot/add-markdown-component

Conversation

CopilotAI commented Jan 14, 2026

Copy link
Copy Markdown
Contributor

Implementation Plan for Markdown Component

  • Explore repository structure and understand component architecture
  • Add markdown rendering library (react-markdown) as dependency
  • Create markdown UI component in src/ui/
  • Create markdown renderer in src/renderers/data-display/
  • Register markdown component in data-display index
  • Add tests for markdown component
  • Build and verify the implementation
  • Create example/demo to verify visual output
  • Run code review and address security concerns
  • Run security scan with CodeQL - No vulnerabilities found
  • Add JSDoc documentation following "Schema First" principle
  • Merge latest code from main branch

Summary

Successfully implemented a new Markdown component for Object UI with comprehensive JSDoc documentation and merged latest changes from main branch.

Changes in This Update

Added JSDoc Documentation

  • Added comprehensive JSDoc comments to MarkdownProps interface
  • Added detailed JSDoc to the markdown renderer component
  • Documentation follows "Schema First" principle for auto-generated docs
  • Includes usage examples and feature descriptions

Merged Main Branch

  • Successfully merged 133 commits from main branch
  • No conflicts encountered
  • All tests pass after merge
  • Build successful

Component Features

  • Full markdown rendering with GitHub Flavored Markdown support
  • XSS protection via rehype-sanitize
  • Dark mode support
  • Tailwind CSS prose styling
  • Comprehensive JSDoc documentation for API reference generation
Original prompt

新建一个makkdown的组件


💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.

CopilotAIand others added 3 commits January 14, 2026 00:05
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR introduces a new Markdown component to Object UI, enabling schema-driven rendering of markdown content with GitHub Flavored Markdown support and XSS protection.

Changes:

  • Added markdown UI component with Tailwind prose styling and security hardening
  • Created markdown renderer component and registered it with ComponentRegistry
  • Added comprehensive test coverage and a working demo in the prototype application

Reviewed changes

Copilot reviewed 7 out of 8 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
packages/components/src/ui/markdown.tsxNew UI component wrapping react-markdown with Tailwind styling and security
packages/components/src/ui/index.tsExport statement for the new markdown component
packages/components/src/renderers/data-display/markdown.tsxRenderer component registering markdown with ComponentRegistry
packages/components/src/renderers/data-display/index.tsImport statement to include markdown renderer
packages/components/src/new-components.test.tsTest case verifying markdown component registration
packages/components/package.jsonAdded react-markdown, remark-gfm, and rehype-sanitize dependencies
examples/prototype/src/App.tsxDemo implementation showcasing markdown component features
Files not reviewed (1)
  • pnpm-lock.yaml: Language not supported

Comment on lines +7 to +10
export interface MarkdownProps {
content: string
className?: string
}

CopilotAIJan 14, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The MarkdownProps interface lacks JSDoc comments. According to Rule #3 ('Schema First' Mindset), every property in the Schema MUST have JSDoc to enable auto-generated documentation for the open-source community. Add JSDoc describing the purpose of 'content' and 'className' properties.

Copilot generated this review using guidance from repository custom instructions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added comprehensive JSDoc documentation to the MarkdownProps interface describing the purpose and supported features of each property. Documentation follows the "Schema First" principle to enable auto-generated API docs. (commit c31876c)

import { Markdown } from '@/ui';

ComponentRegistry.register('markdown',
({ schema, className, ...props }) => (

CopilotAIJan 14, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The renderer component function lacks JSDoc documentation. Add a JSDoc comment explaining that this is a Schema-driven renderer for markdown content, following the 'Schema First' principle outlined in Rule #3.

Copilot generated this review using guidance from repository custom instructions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added detailed JSDoc documentation to the markdown renderer component explaining its schema-driven architecture and usage. Includes example JSON configuration and lists all supported features. (commit c31876c)

CopilotAI changed the title [WIP] Add new markdown componentAdd Markdown component with GFM support and XSS protectionJan 14, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ All checks passed!

  • ✅ Type check passed
  • ✅ Tests passed
  • ✅ Lint check completed

@huangyiirene

Copy link
Copy Markdown
Collaborator

@copilot 从主分支之更新最新代码并修正代码冲突

CopilotAI commented Jan 14, 2026

Copy link
Copy Markdown
ContributorAuthor

@copilot 从主分支之更新最新代码并修正代码冲突

Successfully merged 133 commits from main branch. No conflicts encountered. All tests pass and build is successful. (commit ee033e8)

@github-actions

Copy link
Copy Markdown
Contributor

✅ All checks passed!

  • ✅ Type check passed
  • ✅ Tests passed
  • ✅ Lint check completed

@hotlong
hotlong marked this pull request as ready for review January 14, 2026 01:01
@hotlong
hotlong merged commit 57424b3 into mainJan 14, 2026
1 of 5 checks passed
os-sam pushed a commit that referenced this pull request Aug 31, 2026
…iews that declared none
A view carrying no `calendar:` block used to have a complete-looking calendar
config synthesized for it: `ObjectView` fabricated `startDateField: 'due_date'`
and `titleField: 'name'`, and `ListView`'s calendar branch floored the same two
bindings at `'start_date'` / `'end_date'` one layer down. `ObjectCalendar`
decides whether it has a usable configuration by asking whether a start-date
binding is PRESENT, so the fabrication short-circuited its own refusal screen —
which has existed all along and was simply unreachable from this route.
Both faces now forward only what the author declared. With no binding to
forward, the capability gate stops offering the Calendar toggle to views that
configured none, and a view forced onto the renderer reaches the refusal
screen instead of a plausible, fully wrong one.
Ruled on objectstack#13748 (director batch #19, option A). The spec half —
cross-field validation of a half-written declaration — is objectstack#13817.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Sep 1, 2026
…mes, so the refusal screen becomes reachable (objectstack-ai#7062)
* fix(app-shell,plugin-list): stop inventing calendar field names for views that declared none
A view carrying no `calendar:` block used to have a complete-looking calendar
config synthesized for it: `ObjectView` fabricated `startDateField: 'due_date'`
and `titleField: 'name'`, and `ListView`'s calendar branch floored the same two
bindings at `'start_date'` / `'end_date'` one layer down. `ObjectCalendar`
decides whether it has a usable configuration by asking whether a start-date
binding is PRESENT, so the fabrication short-circuited its own refusal screen —
which has existed all along and was simply unreachable from this route.
Both faces now forward only what the author declared. With no binding to
forward, the capability gate stops offering the Calendar toggle to views that
configured none, and a view forced onto the renderer reaches the refusal
screen instead of a plausible, fully wrong one.
Ruled on objectstack#13748 (director batch objectstack-ai#19, option A). The spec half —
cross-field validation of a half-written declaration — is objectstack#13817.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
* fix(plugin-view): stop inventing calendar bindings on the element route too
`generateViewSchema` runs when no host supplies `renderListView` — the authored
`object-view` element — so it bypasses `ListView` and carried its own copy of
the fabrication (`start_date` / `end_date` / `name`). Same defect, same ruling
(objectstack#13748: no invented field names either way); fixing only the console
route would have left this one producing the same wrong screen.
Also retargets `ObjectView.titleFieldConvergence.test.tsx`: its `calendar`
column pinned the `|| 'name'` floor this card deletes, and the seam count drops
from seven to six. What objectui#6557 owns is unchanged and still pinned.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
* chore(changeset): objectui#7029 — no invented calendar field names
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
---------
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@huangyiirene@hotlong
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Add Markdown component with GFM support and XSS protection - #19

Merged
hotlong merged 7 commits into
mainfrom
copilot/add-markdown-component
Jan 14, 2026
Merged

Add Markdown component with GFM support and XSS protection#19
hotlong merged 7 commits into
mainfrom
copilot/add-markdown-component

Conversation

CopilotAI commented Jan 14, 2026

Copy link
Copy Markdown
Contributor

Implementation Plan for Markdown Component

  • Explore repository structure and understand component architecture
  • Add markdown rendering library (react-markdown) as dependency
  • Create markdown UI component in src/ui/
  • Create markdown renderer in src/renderers/data-display/
  • Register markdown component in data-display index
  • Add tests for markdown component
  • Build and verify the implementation
  • Create example/demo to verify visual output
  • Run code review and address security concerns
  • Run security scan with CodeQL - No vulnerabilities found
  • Add JSDoc documentation following "Schema First" principle
  • Merge latest code from main branch

Summary

Successfully implemented a new Markdown component for Object UI with comprehensive JSDoc documentation and merged latest changes from main branch.

Changes in This Update

Added JSDoc Documentation

  • Added comprehensive JSDoc comments to MarkdownProps interface
  • Added detailed JSDoc to the markdown renderer component
  • Documentation follows "Schema First" principle for auto-generated docs
  • Includes usage examples and feature descriptions

Merged Main Branch

  • Successfully merged 133 commits from main branch
  • No conflicts encountered
  • All tests pass after merge
  • Build successful

Component Features

  • Full markdown rendering with GitHub Flavored Markdown support
  • XSS protection via rehype-sanitize
  • Dark mode support
  • Tailwind CSS prose styling
  • Comprehensive JSDoc documentation for API reference generation
Original prompt

新建一个makkdown的组件


💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.

CopilotAIand others added 3 commits January 14, 2026 00:05
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR introduces a new Markdown component to Object UI, enabling schema-driven rendering of markdown content with GitHub Flavored Markdown support and XSS protection.

Changes:

  • Added markdown UI component with Tailwind prose styling and security hardening
  • Created markdown renderer component and registered it with ComponentRegistry
  • Added comprehensive test coverage and a working demo in the prototype application

Reviewed changes

Copilot reviewed 7 out of 8 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
packages/components/src/ui/markdown.tsxNew UI component wrapping react-markdown with Tailwind styling and security
packages/components/src/ui/index.tsExport statement for the new markdown component
packages/components/src/renderers/data-display/markdown.tsxRenderer component registering markdown with ComponentRegistry
packages/components/src/renderers/data-display/index.tsImport statement to include markdown renderer
packages/components/src/new-components.test.tsTest case verifying markdown component registration
packages/components/package.jsonAdded react-markdown, remark-gfm, and rehype-sanitize dependencies
examples/prototype/src/App.tsxDemo implementation showcasing markdown component features
Files not reviewed (1)
  • pnpm-lock.yaml: Language not supported

Comment on lines +7 to +10
export interface MarkdownProps {
content: string
className?: string
}

CopilotAIJan 14, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The MarkdownProps interface lacks JSDoc comments. According to Rule #3 ('Schema First' Mindset), every property in the Schema MUST have JSDoc to enable auto-generated documentation for the open-source community. Add JSDoc describing the purpose of 'content' and 'className' properties.

Copilot generated this review using guidance from repository custom instructions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added comprehensive JSDoc documentation to the MarkdownProps interface describing the purpose and supported features of each property. Documentation follows the "Schema First" principle to enable auto-generated API docs. (commit c31876c)

import { Markdown } from '@/ui';

ComponentRegistry.register('markdown',
({ schema, className, ...props }) => (

CopilotAIJan 14, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The renderer component function lacks JSDoc documentation. Add a JSDoc comment explaining that this is a Schema-driven renderer for markdown content, following the 'Schema First' principle outlined in Rule #3.

Copilot generated this review using guidance from repository custom instructions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added detailed JSDoc documentation to the markdown renderer component explaining its schema-driven architecture and usage. Includes example JSON configuration and lists all supported features. (commit c31876c)

CopilotAI changed the title [WIP] Add new markdown componentAdd Markdown component with GFM support and XSS protectionJan 14, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ All checks passed!

  • ✅ Type check passed
  • ✅ Tests passed
  • ✅ Lint check completed

@huangyiirene

Copy link
Copy Markdown
Collaborator

@copilot 从主分支之更新最新代码并修正代码冲突

CopilotAI commented Jan 14, 2026

Copy link
Copy Markdown
ContributorAuthor

@copilot 从主分支之更新最新代码并修正代码冲突

Successfully merged 133 commits from main branch. No conflicts encountered. All tests pass and build is successful. (commit ee033e8)

@github-actions

Copy link
Copy Markdown
Contributor

✅ All checks passed!

  • ✅ Type check passed
  • ✅ Tests passed
  • ✅ Lint check completed

@hotlong
hotlong marked this pull request as ready for review January 14, 2026 01:01
@hotlong
hotlong merged commit 57424b3 into mainJan 14, 2026
1 of 5 checks passed
os-sam pushed a commit that referenced this pull request Aug 31, 2026
…iews that declared none
A view carrying no `calendar:` block used to have a complete-looking calendar
config synthesized for it: `ObjectView` fabricated `startDateField: 'due_date'`
and `titleField: 'name'`, and `ListView`'s calendar branch floored the same two
bindings at `'start_date'` / `'end_date'` one layer down. `ObjectCalendar`
decides whether it has a usable configuration by asking whether a start-date
binding is PRESENT, so the fabrication short-circuited its own refusal screen —
which has existed all along and was simply unreachable from this route.
Both faces now forward only what the author declared. With no binding to
forward, the capability gate stops offering the Calendar toggle to views that
configured none, and a view forced onto the renderer reaches the refusal
screen instead of a plausible, fully wrong one.
Ruled on objectstack#13748 (director batch #19, option A). The spec half —
cross-field validation of a half-written declaration — is objectstack#13817.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Sep 1, 2026
…mes, so the refusal screen becomes reachable (objectstack-ai#7062)
* fix(app-shell,plugin-list): stop inventing calendar field names for views that declared none
A view carrying no `calendar:` block used to have a complete-looking calendar
config synthesized for it: `ObjectView` fabricated `startDateField: 'due_date'`
and `titleField: 'name'`, and `ListView`'s calendar branch floored the same two
bindings at `'start_date'` / `'end_date'` one layer down. `ObjectCalendar`
decides whether it has a usable configuration by asking whether a start-date
binding is PRESENT, so the fabrication short-circuited its own refusal screen —
which has existed all along and was simply unreachable from this route.
Both faces now forward only what the author declared. With no binding to
forward, the capability gate stops offering the Calendar toggle to views that
configured none, and a view forced onto the renderer reaches the refusal
screen instead of a plausible, fully wrong one.
Ruled on objectstack#13748 (director batch objectstack-ai#19, option A). The spec half —
cross-field validation of a half-written declaration — is objectstack#13817.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
* fix(plugin-view): stop inventing calendar bindings on the element route too
`generateViewSchema` runs when no host supplies `renderListView` — the authored
`object-view` element — so it bypasses `ListView` and carried its own copy of
the fabrication (`start_date` / `end_date` / `name`). Same defect, same ruling
(objectstack#13748: no invented field names either way); fixing only the console
route would have left this one producing the same wrong screen.
Also retargets `ObjectView.titleFieldConvergence.test.tsx`: its `calendar`
column pinned the `|| 'name'` floor this card deletes, and the seam count drops
from seven to six. What objectui#6557 owns is unchanged and still pinned.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
* chore(changeset): objectui#7029 — no invented calendar field names
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
---------
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@huangyiirene@hotlong
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add Markdown component with GFM support and XSS protection - #19

Merged
hotlong merged 7 commits into
mainfrom
copilot/add-markdown-component
Jan 14, 2026
Merged

Add Markdown component with GFM support and XSS protection#19
hotlong merged 7 commits into
mainfrom
copilot/add-markdown-component

Conversation

CopilotAI commented Jan 14, 2026

Copy link
Copy Markdown
Contributor

Implementation Plan for Markdown Component

  • Explore repository structure and understand component architecture
  • Add markdown rendering library (react-markdown) as dependency
  • Create markdown UI component in src/ui/
  • Create markdown renderer in src/renderers/data-display/
  • Register markdown component in data-display index
  • Add tests for markdown component
  • Build and verify the implementation
  • Create example/demo to verify visual output
  • Run code review and address security concerns
  • Run security scan with CodeQL - No vulnerabilities found
  • Add JSDoc documentation following "Schema First" principle
  • Merge latest code from main branch

Summary

Successfully implemented a new Markdown component for Object UI with comprehensive JSDoc documentation and merged latest changes from main branch.

Changes in This Update

Added JSDoc Documentation

  • Added comprehensive JSDoc comments to MarkdownProps interface
  • Added detailed JSDoc to the markdown renderer component
  • Documentation follows "Schema First" principle for auto-generated docs
  • Includes usage examples and feature descriptions

Merged Main Branch

  • Successfully merged 133 commits from main branch
  • No conflicts encountered
  • All tests pass after merge
  • Build successful

Component Features

  • Full markdown rendering with GitHub Flavored Markdown support
  • XSS protection via rehype-sanitize
  • Dark mode support
  • Tailwind CSS prose styling
  • Comprehensive JSDoc documentation for API reference generation
Original prompt

新建一个makkdown的组件


💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.

CopilotAIand others added 3 commits January 14, 2026 00:05
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR introduces a new Markdown component to Object UI, enabling schema-driven rendering of markdown content with GitHub Flavored Markdown support and XSS protection.

Changes:

  • Added markdown UI component with Tailwind prose styling and security hardening
  • Created markdown renderer component and registered it with ComponentRegistry
  • Added comprehensive test coverage and a working demo in the prototype application

Reviewed changes

Copilot reviewed 7 out of 8 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
packages/components/src/ui/markdown.tsxNew UI component wrapping react-markdown with Tailwind styling and security
packages/components/src/ui/index.tsExport statement for the new markdown component
packages/components/src/renderers/data-display/markdown.tsxRenderer component registering markdown with ComponentRegistry
packages/components/src/renderers/data-display/index.tsImport statement to include markdown renderer
packages/components/src/new-components.test.tsTest case verifying markdown component registration
packages/components/package.jsonAdded react-markdown, remark-gfm, and rehype-sanitize dependencies
examples/prototype/src/App.tsxDemo implementation showcasing markdown component features
Files not reviewed (1)
  • pnpm-lock.yaml: Language not supported

Comment on lines +7 to +10
export interface MarkdownProps {
content: string
className?: string
}

CopilotAIJan 14, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The MarkdownProps interface lacks JSDoc comments. According to Rule #3 ('Schema First' Mindset), every property in the Schema MUST have JSDoc to enable auto-generated documentation for the open-source community. Add JSDoc describing the purpose of 'content' and 'className' properties.

Copilot generated this review using guidance from repository custom instructions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added comprehensive JSDoc documentation to the MarkdownProps interface describing the purpose and supported features of each property. Documentation follows the "Schema First" principle to enable auto-generated API docs. (commit c31876c)

import { Markdown } from '@/ui';

ComponentRegistry.register('markdown',
({ schema, className, ...props }) => (

CopilotAIJan 14, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The renderer component function lacks JSDoc documentation. Add a JSDoc comment explaining that this is a Schema-driven renderer for markdown content, following the 'Schema First' principle outlined in Rule #3.

Copilot generated this review using guidance from repository custom instructions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added detailed JSDoc documentation to the markdown renderer component explaining its schema-driven architecture and usage. Includes example JSON configuration and lists all supported features. (commit c31876c)

CopilotAI changed the title [WIP] Add new markdown componentAdd Markdown component with GFM support and XSS protectionJan 14, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ All checks passed!

  • ✅ Type check passed
  • ✅ Tests passed
  • ✅ Lint check completed

@huangyiirene

Copy link
Copy Markdown
Collaborator

@copilot 从主分支之更新最新代码并修正代码冲突

CopilotAI commented Jan 14, 2026

Copy link
Copy Markdown
ContributorAuthor

@copilot 从主分支之更新最新代码并修正代码冲突

Successfully merged 133 commits from main branch. No conflicts encountered. All tests pass and build is successful. (commit ee033e8)

@github-actions

Copy link
Copy Markdown
Contributor

✅ All checks passed!

  • ✅ Type check passed
  • ✅ Tests passed
  • ✅ Lint check completed

@hotlong
hotlong marked this pull request as ready for review January 14, 2026 01:01
@hotlong
hotlong merged commit 57424b3 into mainJan 14, 2026
1 of 5 checks passed
os-sam pushed a commit that referenced this pull request Aug 31, 2026
…iews that declared none
A view carrying no `calendar:` block used to have a complete-looking calendar
config synthesized for it: `ObjectView` fabricated `startDateField: 'due_date'`
and `titleField: 'name'`, and `ListView`'s calendar branch floored the same two
bindings at `'start_date'` / `'end_date'` one layer down. `ObjectCalendar`
decides whether it has a usable configuration by asking whether a start-date
binding is PRESENT, so the fabrication short-circuited its own refusal screen —
which has existed all along and was simply unreachable from this route.
Both faces now forward only what the author declared. With no binding to
forward, the capability gate stops offering the Calendar toggle to views that
configured none, and a view forced onto the renderer reaches the refusal
screen instead of a plausible, fully wrong one.
Ruled on objectstack#13748 (director batch #19, option A). The spec half —
cross-field validation of a half-written declaration — is objectstack#13817.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Sep 1, 2026
…mes, so the refusal screen becomes reachable (objectstack-ai#7062)
* fix(app-shell,plugin-list): stop inventing calendar field names for views that declared none
A view carrying no `calendar:` block used to have a complete-looking calendar
config synthesized for it: `ObjectView` fabricated `startDateField: 'due_date'`
and `titleField: 'name'`, and `ListView`'s calendar branch floored the same two
bindings at `'start_date'` / `'end_date'` one layer down. `ObjectCalendar`
decides whether it has a usable configuration by asking whether a start-date
binding is PRESENT, so the fabrication short-circuited its own refusal screen —
which has existed all along and was simply unreachable from this route.
Both faces now forward only what the author declared. With no binding to
forward, the capability gate stops offering the Calendar toggle to views that
configured none, and a view forced onto the renderer reaches the refusal
screen instead of a plausible, fully wrong one.
Ruled on objectstack#13748 (director batch objectstack-ai#19, option A). The spec half —
cross-field validation of a half-written declaration — is objectstack#13817.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
* fix(plugin-view): stop inventing calendar bindings on the element route too
`generateViewSchema` runs when no host supplies `renderListView` — the authored
`object-view` element — so it bypasses `ListView` and carried its own copy of
the fabrication (`start_date` / `end_date` / `name`). Same defect, same ruling
(objectstack#13748: no invented field names either way); fixing only the console
route would have left this one producing the same wrong screen.
Also retargets `ObjectView.titleFieldConvergence.test.tsx`: its `calendar`
column pinned the `|| 'name'` floor this card deletes, and the seam count drops
from seven to six. What objectui#6557 owns is unchanged and still pinned.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
* chore(changeset): objectui#7029 — no invented calendar field names
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
---------
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@huangyiirene@hotlong
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add Markdown component with GFM support and XSS protection - #19

Merged
hotlong merged 7 commits into
mainfrom
copilot/add-markdown-component
Jan 14, 2026
Merged

Add Markdown component with GFM support and XSS protection#19
hotlong merged 7 commits into
mainfrom
copilot/add-markdown-component

Conversation

CopilotAI commented Jan 14, 2026

Copy link
Copy Markdown
Contributor

Implementation Plan for Markdown Component

  • Explore repository structure and understand component architecture
  • Add markdown rendering library (react-markdown) as dependency
  • Create markdown UI component in src/ui/
  • Create markdown renderer in src/renderers/data-display/
  • Register markdown component in data-display index
  • Add tests for markdown component
  • Build and verify the implementation
  • Create example/demo to verify visual output
  • Run code review and address security concerns
  • Run security scan with CodeQL - No vulnerabilities found
  • Add JSDoc documentation following "Schema First" principle
  • Merge latest code from main branch

Summary

Successfully implemented a new Markdown component for Object UI with comprehensive JSDoc documentation and merged latest changes from main branch.

Changes in This Update

Added JSDoc Documentation

  • Added comprehensive JSDoc comments to MarkdownProps interface
  • Added detailed JSDoc to the markdown renderer component
  • Documentation follows "Schema First" principle for auto-generated docs
  • Includes usage examples and feature descriptions

Merged Main Branch

  • Successfully merged 133 commits from main branch
  • No conflicts encountered
  • All tests pass after merge
  • Build successful

Component Features

  • Full markdown rendering with GitHub Flavored Markdown support
  • XSS protection via rehype-sanitize
  • Dark mode support
  • Tailwind CSS prose styling
  • Comprehensive JSDoc documentation for API reference generation
Original prompt

新建一个makkdown的组件


💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.

CopilotAIand others added 3 commits January 14, 2026 00:05
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR introduces a new Markdown component to Object UI, enabling schema-driven rendering of markdown content with GitHub Flavored Markdown support and XSS protection.

Changes:

  • Added markdown UI component with Tailwind prose styling and security hardening
  • Created markdown renderer component and registered it with ComponentRegistry
  • Added comprehensive test coverage and a working demo in the prototype application

Reviewed changes

Copilot reviewed 7 out of 8 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
packages/components/src/ui/markdown.tsxNew UI component wrapping react-markdown with Tailwind styling and security
packages/components/src/ui/index.tsExport statement for the new markdown component
packages/components/src/renderers/data-display/markdown.tsxRenderer component registering markdown with ComponentRegistry
packages/components/src/renderers/data-display/index.tsImport statement to include markdown renderer
packages/components/src/new-components.test.tsTest case verifying markdown component registration
packages/components/package.jsonAdded react-markdown, remark-gfm, and rehype-sanitize dependencies
examples/prototype/src/App.tsxDemo implementation showcasing markdown component features
Files not reviewed (1)
  • pnpm-lock.yaml: Language not supported

Comment on lines +7 to +10
export interface MarkdownProps {
content: string
className?: string
}

CopilotAIJan 14, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The MarkdownProps interface lacks JSDoc comments. According to Rule #3 ('Schema First' Mindset), every property in the Schema MUST have JSDoc to enable auto-generated documentation for the open-source community. Add JSDoc describing the purpose of 'content' and 'className' properties.

Copilot generated this review using guidance from repository custom instructions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added comprehensive JSDoc documentation to the MarkdownProps interface describing the purpose and supported features of each property. Documentation follows the "Schema First" principle to enable auto-generated API docs. (commit c31876c)

import { Markdown } from '@/ui';

ComponentRegistry.register('markdown',
({ schema, className, ...props }) => (

CopilotAIJan 14, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The renderer component function lacks JSDoc documentation. Add a JSDoc comment explaining that this is a Schema-driven renderer for markdown content, following the 'Schema First' principle outlined in Rule #3.

Copilot generated this review using guidance from repository custom instructions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added detailed JSDoc documentation to the markdown renderer component explaining its schema-driven architecture and usage. Includes example JSON configuration and lists all supported features. (commit c31876c)

CopilotAI changed the title [WIP] Add new markdown componentAdd Markdown component with GFM support and XSS protectionJan 14, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ All checks passed!

  • ✅ Type check passed
  • ✅ Tests passed
  • ✅ Lint check completed

@huangyiirene

Copy link
Copy Markdown
Collaborator

@copilot 从主分支之更新最新代码并修正代码冲突

CopilotAI commented Jan 14, 2026

Copy link
Copy Markdown
ContributorAuthor

@copilot 从主分支之更新最新代码并修正代码冲突

Successfully merged 133 commits from main branch. No conflicts encountered. All tests pass and build is successful. (commit ee033e8)

@github-actions

Copy link
Copy Markdown
Contributor

✅ All checks passed!

  • ✅ Type check passed
  • ✅ Tests passed
  • ✅ Lint check completed

@hotlong
hotlong marked this pull request as ready for review January 14, 2026 01:01
@hotlong
hotlong merged commit 57424b3 into mainJan 14, 2026
1 of 5 checks passed
os-sam pushed a commit that referenced this pull request Aug 31, 2026
…iews that declared none
A view carrying no `calendar:` block used to have a complete-looking calendar
config synthesized for it: `ObjectView` fabricated `startDateField: 'due_date'`
and `titleField: 'name'`, and `ListView`'s calendar branch floored the same two
bindings at `'start_date'` / `'end_date'` one layer down. `ObjectCalendar`
decides whether it has a usable configuration by asking whether a start-date
binding is PRESENT, so the fabrication short-circuited its own refusal screen —
which has existed all along and was simply unreachable from this route.
Both faces now forward only what the author declared. With no binding to
forward, the capability gate stops offering the Calendar toggle to views that
configured none, and a view forced onto the renderer reaches the refusal
screen instead of a plausible, fully wrong one.
Ruled on objectstack#13748 (director batch #19, option A). The spec half —
cross-field validation of a half-written declaration — is objectstack#13817.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Sep 1, 2026
…mes, so the refusal screen becomes reachable (objectstack-ai#7062)
* fix(app-shell,plugin-list): stop inventing calendar field names for views that declared none
A view carrying no `calendar:` block used to have a complete-looking calendar
config synthesized for it: `ObjectView` fabricated `startDateField: 'due_date'`
and `titleField: 'name'`, and `ListView`'s calendar branch floored the same two
bindings at `'start_date'` / `'end_date'` one layer down. `ObjectCalendar`
decides whether it has a usable configuration by asking whether a start-date
binding is PRESENT, so the fabrication short-circuited its own refusal screen —
which has existed all along and was simply unreachable from this route.
Both faces now forward only what the author declared. With no binding to
forward, the capability gate stops offering the Calendar toggle to views that
configured none, and a view forced onto the renderer reaches the refusal
screen instead of a plausible, fully wrong one.
Ruled on objectstack#13748 (director batch objectstack-ai#19, option A). The spec half —
cross-field validation of a half-written declaration — is objectstack#13817.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
* fix(plugin-view): stop inventing calendar bindings on the element route too
`generateViewSchema` runs when no host supplies `renderListView` — the authored
`object-view` element — so it bypasses `ListView` and carried its own copy of
the fabrication (`start_date` / `end_date` / `name`). Same defect, same ruling
(objectstack#13748: no invented field names either way); fixing only the console
route would have left this one producing the same wrong screen.
Also retargets `ObjectView.titleFieldConvergence.test.tsx`: its `calendar`
column pinned the `|| 'name'` floor this card deletes, and the seam count drops
from seven to six. What objectui#6557 owns is unchanged and still pinned.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
* chore(changeset): objectui#7029 — no invented calendar field names
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
---------
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@huangyiirene@hotlong
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Add Markdown component with GFM support and XSS protection - #19

Merged
hotlong merged 7 commits into
mainfrom
copilot/add-markdown-component
Jan 14, 2026
Merged

Add Markdown component with GFM support and XSS protection#19
hotlong merged 7 commits into
mainfrom
copilot/add-markdown-component

Conversation

CopilotAI commented Jan 14, 2026

Copy link
Copy Markdown
Contributor

Implementation Plan for Markdown Component

  • Explore repository structure and understand component architecture
  • Add markdown rendering library (react-markdown) as dependency
  • Create markdown UI component in src/ui/
  • Create markdown renderer in src/renderers/data-display/
  • Register markdown component in data-display index
  • Add tests for markdown component
  • Build and verify the implementation
  • Create example/demo to verify visual output
  • Run code review and address security concerns
  • Run security scan with CodeQL - No vulnerabilities found
  • Add JSDoc documentation following "Schema First" principle
  • Merge latest code from main branch

Summary

Successfully implemented a new Markdown component for Object UI with comprehensive JSDoc documentation and merged latest changes from main branch.

Changes in This Update

Added JSDoc Documentation

  • Added comprehensive JSDoc comments to MarkdownProps interface
  • Added detailed JSDoc to the markdown renderer component
  • Documentation follows "Schema First" principle for auto-generated docs
  • Includes usage examples and feature descriptions

Merged Main Branch

  • Successfully merged 133 commits from main branch
  • No conflicts encountered
  • All tests pass after merge
  • Build successful

Component Features

  • Full markdown rendering with GitHub Flavored Markdown support
  • XSS protection via rehype-sanitize
  • Dark mode support
  • Tailwind CSS prose styling
  • Comprehensive JSDoc documentation for API reference generation
Original prompt

新建一个makkdown的组件


💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.

CopilotAIand others added 3 commits January 14, 2026 00:05
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR introduces a new Markdown component to Object UI, enabling schema-driven rendering of markdown content with GitHub Flavored Markdown support and XSS protection.

Changes:

  • Added markdown UI component with Tailwind prose styling and security hardening
  • Created markdown renderer component and registered it with ComponentRegistry
  • Added comprehensive test coverage and a working demo in the prototype application

Reviewed changes

Copilot reviewed 7 out of 8 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
packages/components/src/ui/markdown.tsxNew UI component wrapping react-markdown with Tailwind styling and security
packages/components/src/ui/index.tsExport statement for the new markdown component
packages/components/src/renderers/data-display/markdown.tsxRenderer component registering markdown with ComponentRegistry
packages/components/src/renderers/data-display/index.tsImport statement to include markdown renderer
packages/components/src/new-components.test.tsTest case verifying markdown component registration
packages/components/package.jsonAdded react-markdown, remark-gfm, and rehype-sanitize dependencies
examples/prototype/src/App.tsxDemo implementation showcasing markdown component features
Files not reviewed (1)
  • pnpm-lock.yaml: Language not supported

Comment on lines +7 to +10
export interface MarkdownProps {
content: string
className?: string
}

CopilotAIJan 14, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The MarkdownProps interface lacks JSDoc comments. According to Rule #3 ('Schema First' Mindset), every property in the Schema MUST have JSDoc to enable auto-generated documentation for the open-source community. Add JSDoc describing the purpose of 'content' and 'className' properties.

Copilot generated this review using guidance from repository custom instructions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added comprehensive JSDoc documentation to the MarkdownProps interface describing the purpose and supported features of each property. Documentation follows the "Schema First" principle to enable auto-generated API docs. (commit c31876c)

import { Markdown } from '@/ui';

ComponentRegistry.register('markdown',
({ schema, className, ...props }) => (

CopilotAIJan 14, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The renderer component function lacks JSDoc documentation. Add a JSDoc comment explaining that this is a Schema-driven renderer for markdown content, following the 'Schema First' principle outlined in Rule #3.

Copilot generated this review using guidance from repository custom instructions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added detailed JSDoc documentation to the markdown renderer component explaining its schema-driven architecture and usage. Includes example JSON configuration and lists all supported features. (commit c31876c)

CopilotAI changed the title [WIP] Add new markdown componentAdd Markdown component with GFM support and XSS protectionJan 14, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ All checks passed!

  • ✅ Type check passed
  • ✅ Tests passed
  • ✅ Lint check completed

@huangyiirene

Copy link
Copy Markdown
Collaborator

@copilot 从主分支之更新最新代码并修正代码冲突

CopilotAI commented Jan 14, 2026

Copy link
Copy Markdown
ContributorAuthor

@copilot 从主分支之更新最新代码并修正代码冲突

Successfully merged 133 commits from main branch. No conflicts encountered. All tests pass and build is successful. (commit ee033e8)

@github-actions

Copy link
Copy Markdown
Contributor

✅ All checks passed!

  • ✅ Type check passed
  • ✅ Tests passed
  • ✅ Lint check completed

@hotlong
hotlong marked this pull request as ready for review January 14, 2026 01:01
@hotlong
hotlong merged commit 57424b3 into mainJan 14, 2026
1 of 5 checks passed
os-sam pushed a commit that referenced this pull request Aug 31, 2026
…iews that declared none
A view carrying no `calendar:` block used to have a complete-looking calendar
config synthesized for it: `ObjectView` fabricated `startDateField: 'due_date'`
and `titleField: 'name'`, and `ListView`'s calendar branch floored the same two
bindings at `'start_date'` / `'end_date'` one layer down. `ObjectCalendar`
decides whether it has a usable configuration by asking whether a start-date
binding is PRESENT, so the fabrication short-circuited its own refusal screen —
which has existed all along and was simply unreachable from this route.
Both faces now forward only what the author declared. With no binding to
forward, the capability gate stops offering the Calendar toggle to views that
configured none, and a view forced onto the renderer reaches the refusal
screen instead of a plausible, fully wrong one.
Ruled on objectstack#13748 (director batch #19, option A). The spec half —
cross-field validation of a half-written declaration — is objectstack#13817.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Sep 1, 2026
…mes, so the refusal screen becomes reachable (objectstack-ai#7062)
* fix(app-shell,plugin-list): stop inventing calendar field names for views that declared none
A view carrying no `calendar:` block used to have a complete-looking calendar
config synthesized for it: `ObjectView` fabricated `startDateField: 'due_date'`
and `titleField: 'name'`, and `ListView`'s calendar branch floored the same two
bindings at `'start_date'` / `'end_date'` one layer down. `ObjectCalendar`
decides whether it has a usable configuration by asking whether a start-date
binding is PRESENT, so the fabrication short-circuited its own refusal screen —
which has existed all along and was simply unreachable from this route.
Both faces now forward only what the author declared. With no binding to
forward, the capability gate stops offering the Calendar toggle to views that
configured none, and a view forced onto the renderer reaches the refusal
screen instead of a plausible, fully wrong one.
Ruled on objectstack#13748 (director batch objectstack-ai#19, option A). The spec half —
cross-field validation of a half-written declaration — is objectstack#13817.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
* fix(plugin-view): stop inventing calendar bindings on the element route too
`generateViewSchema` runs when no host supplies `renderListView` — the authored
`object-view` element — so it bypasses `ListView` and carried its own copy of
the fabrication (`start_date` / `end_date` / `name`). Same defect, same ruling
(objectstack#13748: no invented field names either way); fixing only the console
route would have left this one producing the same wrong screen.
Also retargets `ObjectView.titleFieldConvergence.test.tsx`: its `calendar`
column pinned the `|| 'name'` floor this card deletes, and the seam count drops
from seven to six. What objectui#6557 owns is unchanged and still pinned.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
* chore(changeset): objectui#7029 — no invented calendar field names
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
---------
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@huangyiirene@hotlong
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add Markdown component with GFM support and XSS protection - #19

Merged
hotlong merged 7 commits into
mainfrom
copilot/add-markdown-component
Jan 14, 2026
Merged

Add Markdown component with GFM support and XSS protection#19
hotlong merged 7 commits into
mainfrom
copilot/add-markdown-component

Conversation

CopilotAI commented Jan 14, 2026

Copy link
Copy Markdown
Contributor

Implementation Plan for Markdown Component

  • Explore repository structure and understand component architecture
  • Add markdown rendering library (react-markdown) as dependency
  • Create markdown UI component in src/ui/
  • Create markdown renderer in src/renderers/data-display/
  • Register markdown component in data-display index
  • Add tests for markdown component
  • Build and verify the implementation
  • Create example/demo to verify visual output
  • Run code review and address security concerns
  • Run security scan with CodeQL - No vulnerabilities found
  • Add JSDoc documentation following "Schema First" principle
  • Merge latest code from main branch

Summary

Successfully implemented a new Markdown component for Object UI with comprehensive JSDoc documentation and merged latest changes from main branch.

Changes in This Update

Added JSDoc Documentation

  • Added comprehensive JSDoc comments to MarkdownProps interface
  • Added detailed JSDoc to the markdown renderer component
  • Documentation follows "Schema First" principle for auto-generated docs
  • Includes usage examples and feature descriptions

Merged Main Branch

  • Successfully merged 133 commits from main branch
  • No conflicts encountered
  • All tests pass after merge
  • Build successful

Component Features

  • Full markdown rendering with GitHub Flavored Markdown support
  • XSS protection via rehype-sanitize
  • Dark mode support
  • Tailwind CSS prose styling
  • Comprehensive JSDoc documentation for API reference generation
Original prompt

新建一个makkdown的组件


💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.

CopilotAIand others added 3 commits January 14, 2026 00:05
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR introduces a new Markdown component to Object UI, enabling schema-driven rendering of markdown content with GitHub Flavored Markdown support and XSS protection.

Changes:

  • Added markdown UI component with Tailwind prose styling and security hardening
  • Created markdown renderer component and registered it with ComponentRegistry
  • Added comprehensive test coverage and a working demo in the prototype application

Reviewed changes

Copilot reviewed 7 out of 8 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
packages/components/src/ui/markdown.tsxNew UI component wrapping react-markdown with Tailwind styling and security
packages/components/src/ui/index.tsExport statement for the new markdown component
packages/components/src/renderers/data-display/markdown.tsxRenderer component registering markdown with ComponentRegistry
packages/components/src/renderers/data-display/index.tsImport statement to include markdown renderer
packages/components/src/new-components.test.tsTest case verifying markdown component registration
packages/components/package.jsonAdded react-markdown, remark-gfm, and rehype-sanitize dependencies
examples/prototype/src/App.tsxDemo implementation showcasing markdown component features
Files not reviewed (1)
  • pnpm-lock.yaml: Language not supported

Comment on lines +7 to +10
export interface MarkdownProps {
content: string
className?: string
}

CopilotAIJan 14, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The MarkdownProps interface lacks JSDoc comments. According to Rule #3 ('Schema First' Mindset), every property in the Schema MUST have JSDoc to enable auto-generated documentation for the open-source community. Add JSDoc describing the purpose of 'content' and 'className' properties.

Copilot generated this review using guidance from repository custom instructions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added comprehensive JSDoc documentation to the MarkdownProps interface describing the purpose and supported features of each property. Documentation follows the "Schema First" principle to enable auto-generated API docs. (commit c31876c)

import { Markdown } from '@/ui';

ComponentRegistry.register('markdown',
({ schema, className, ...props }) => (

CopilotAIJan 14, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The renderer component function lacks JSDoc documentation. Add a JSDoc comment explaining that this is a Schema-driven renderer for markdown content, following the 'Schema First' principle outlined in Rule #3.

Copilot generated this review using guidance from repository custom instructions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added detailed JSDoc documentation to the markdown renderer component explaining its schema-driven architecture and usage. Includes example JSON configuration and lists all supported features. (commit c31876c)

CopilotAI changed the title [WIP] Add new markdown componentAdd Markdown component with GFM support and XSS protectionJan 14, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ All checks passed!

  • ✅ Type check passed
  • ✅ Tests passed
  • ✅ Lint check completed

@huangyiirene

Copy link
Copy Markdown
Collaborator

@copilot 从主分支之更新最新代码并修正代码冲突

CopilotAI commented Jan 14, 2026

Copy link
Copy Markdown
ContributorAuthor

@copilot 从主分支之更新最新代码并修正代码冲突

Successfully merged 133 commits from main branch. No conflicts encountered. All tests pass and build is successful. (commit ee033e8)

@github-actions

Copy link
Copy Markdown
Contributor

✅ All checks passed!

  • ✅ Type check passed
  • ✅ Tests passed
  • ✅ Lint check completed

@hotlong
hotlong marked this pull request as ready for review January 14, 2026 01:01
@hotlong
hotlong merged commit 57424b3 into mainJan 14, 2026
1 of 5 checks passed
os-sam pushed a commit that referenced this pull request Aug 31, 2026
…iews that declared none
A view carrying no `calendar:` block used to have a complete-looking calendar
config synthesized for it: `ObjectView` fabricated `startDateField: 'due_date'`
and `titleField: 'name'`, and `ListView`'s calendar branch floored the same two
bindings at `'start_date'` / `'end_date'` one layer down. `ObjectCalendar`
decides whether it has a usable configuration by asking whether a start-date
binding is PRESENT, so the fabrication short-circuited its own refusal screen —
which has existed all along and was simply unreachable from this route.
Both faces now forward only what the author declared. With no binding to
forward, the capability gate stops offering the Calendar toggle to views that
configured none, and a view forced onto the renderer reaches the refusal
screen instead of a plausible, fully wrong one.
Ruled on objectstack#13748 (director batch #19, option A). The spec half —
cross-field validation of a half-written declaration — is objectstack#13817.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Sep 1, 2026
…mes, so the refusal screen becomes reachable (objectstack-ai#7062)
* fix(app-shell,plugin-list): stop inventing calendar field names for views that declared none
A view carrying no `calendar:` block used to have a complete-looking calendar
config synthesized for it: `ObjectView` fabricated `startDateField: 'due_date'`
and `titleField: 'name'`, and `ListView`'s calendar branch floored the same two
bindings at `'start_date'` / `'end_date'` one layer down. `ObjectCalendar`
decides whether it has a usable configuration by asking whether a start-date
binding is PRESENT, so the fabrication short-circuited its own refusal screen —
which has existed all along and was simply unreachable from this route.
Both faces now forward only what the author declared. With no binding to
forward, the capability gate stops offering the Calendar toggle to views that
configured none, and a view forced onto the renderer reaches the refusal
screen instead of a plausible, fully wrong one.
Ruled on objectstack#13748 (director batch objectstack-ai#19, option A). The spec half —
cross-field validation of a half-written declaration — is objectstack#13817.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
* fix(plugin-view): stop inventing calendar bindings on the element route too
`generateViewSchema` runs when no host supplies `renderListView` — the authored
`object-view` element — so it bypasses `ListView` and carried its own copy of
the fabrication (`start_date` / `end_date` / `name`). Same defect, same ruling
(objectstack#13748: no invented field names either way); fixing only the console
route would have left this one producing the same wrong screen.
Also retargets `ObjectView.titleFieldConvergence.test.tsx`: its `calendar`
column pinned the `|| 'name'` floor this card deletes, and the seam count drops
from seven to six. What objectui#6557 owns is unchanged and still pinned.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
* chore(changeset): objectui#7029 — no invented calendar field names
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
---------
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@huangyiirene@hotlong
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add Markdown component with GFM support and XSS protection - #19

Merged
hotlong merged 7 commits into
mainfrom
copilot/add-markdown-component
Jan 14, 2026
Merged

Add Markdown component with GFM support and XSS protection#19
hotlong merged 7 commits into
mainfrom
copilot/add-markdown-component

Conversation

CopilotAI commented Jan 14, 2026

Copy link
Copy Markdown
Contributor

Implementation Plan for Markdown Component

  • Explore repository structure and understand component architecture
  • Add markdown rendering library (react-markdown) as dependency
  • Create markdown UI component in src/ui/
  • Create markdown renderer in src/renderers/data-display/
  • Register markdown component in data-display index
  • Add tests for markdown component
  • Build and verify the implementation
  • Create example/demo to verify visual output
  • Run code review and address security concerns
  • Run security scan with CodeQL - No vulnerabilities found
  • Add JSDoc documentation following "Schema First" principle
  • Merge latest code from main branch

Summary

Successfully implemented a new Markdown component for Object UI with comprehensive JSDoc documentation and merged latest changes from main branch.

Changes in This Update

Added JSDoc Documentation

  • Added comprehensive JSDoc comments to MarkdownProps interface
  • Added detailed JSDoc to the markdown renderer component
  • Documentation follows "Schema First" principle for auto-generated docs
  • Includes usage examples and feature descriptions

Merged Main Branch

  • Successfully merged 133 commits from main branch
  • No conflicts encountered
  • All tests pass after merge
  • Build successful

Component Features

  • Full markdown rendering with GitHub Flavored Markdown support
  • XSS protection via rehype-sanitize
  • Dark mode support
  • Tailwind CSS prose styling
  • Comprehensive JSDoc documentation for API reference generation
Original prompt

新建一个makkdown的组件


💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.

CopilotAIand others added 3 commits January 14, 2026 00:05
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR introduces a new Markdown component to Object UI, enabling schema-driven rendering of markdown content with GitHub Flavored Markdown support and XSS protection.

Changes:

  • Added markdown UI component with Tailwind prose styling and security hardening
  • Created markdown renderer component and registered it with ComponentRegistry
  • Added comprehensive test coverage and a working demo in the prototype application

Reviewed changes

Copilot reviewed 7 out of 8 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
packages/components/src/ui/markdown.tsxNew UI component wrapping react-markdown with Tailwind styling and security
packages/components/src/ui/index.tsExport statement for the new markdown component
packages/components/src/renderers/data-display/markdown.tsxRenderer component registering markdown with ComponentRegistry
packages/components/src/renderers/data-display/index.tsImport statement to include markdown renderer
packages/components/src/new-components.test.tsTest case verifying markdown component registration
packages/components/package.jsonAdded react-markdown, remark-gfm, and rehype-sanitize dependencies
examples/prototype/src/App.tsxDemo implementation showcasing markdown component features
Files not reviewed (1)
  • pnpm-lock.yaml: Language not supported

Comment on lines +7 to +10
export interface MarkdownProps {
content: string
className?: string
}

CopilotAIJan 14, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The MarkdownProps interface lacks JSDoc comments. According to Rule #3 ('Schema First' Mindset), every property in the Schema MUST have JSDoc to enable auto-generated documentation for the open-source community. Add JSDoc describing the purpose of 'content' and 'className' properties.

Copilot generated this review using guidance from repository custom instructions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added comprehensive JSDoc documentation to the MarkdownProps interface describing the purpose and supported features of each property. Documentation follows the "Schema First" principle to enable auto-generated API docs. (commit c31876c)

import { Markdown } from '@/ui';

ComponentRegistry.register('markdown',
({ schema, className, ...props }) => (

CopilotAIJan 14, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The renderer component function lacks JSDoc documentation. Add a JSDoc comment explaining that this is a Schema-driven renderer for markdown content, following the 'Schema First' principle outlined in Rule #3.

Copilot generated this review using guidance from repository custom instructions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added detailed JSDoc documentation to the markdown renderer component explaining its schema-driven architecture and usage. Includes example JSON configuration and lists all supported features. (commit c31876c)

CopilotAI changed the title [WIP] Add new markdown componentAdd Markdown component with GFM support and XSS protectionJan 14, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ All checks passed!

  • ✅ Type check passed
  • ✅ Tests passed
  • ✅ Lint check completed

@huangyiirene

Copy link
Copy Markdown
Collaborator

@copilot 从主分支之更新最新代码并修正代码冲突

CopilotAI commented Jan 14, 2026

Copy link
Copy Markdown
ContributorAuthor

@copilot 从主分支之更新最新代码并修正代码冲突

Successfully merged 133 commits from main branch. No conflicts encountered. All tests pass and build is successful. (commit ee033e8)

@github-actions

Copy link
Copy Markdown
Contributor

✅ All checks passed!

  • ✅ Type check passed
  • ✅ Tests passed
  • ✅ Lint check completed

@hotlong
hotlong marked this pull request as ready for review January 14, 2026 01:01
@hotlong
hotlong merged commit 57424b3 into mainJan 14, 2026
1 of 5 checks passed
os-sam pushed a commit that referenced this pull request Aug 31, 2026
…iews that declared none
A view carrying no `calendar:` block used to have a complete-looking calendar
config synthesized for it: `ObjectView` fabricated `startDateField: 'due_date'`
and `titleField: 'name'`, and `ListView`'s calendar branch floored the same two
bindings at `'start_date'` / `'end_date'` one layer down. `ObjectCalendar`
decides whether it has a usable configuration by asking whether a start-date
binding is PRESENT, so the fabrication short-circuited its own refusal screen —
which has existed all along and was simply unreachable from this route.
Both faces now forward only what the author declared. With no binding to
forward, the capability gate stops offering the Calendar toggle to views that
configured none, and a view forced onto the renderer reaches the refusal
screen instead of a plausible, fully wrong one.
Ruled on objectstack#13748 (director batch #19, option A). The spec half —
cross-field validation of a half-written declaration — is objectstack#13817.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Sep 1, 2026
…mes, so the refusal screen becomes reachable (objectstack-ai#7062)
* fix(app-shell,plugin-list): stop inventing calendar field names for views that declared none
A view carrying no `calendar:` block used to have a complete-looking calendar
config synthesized for it: `ObjectView` fabricated `startDateField: 'due_date'`
and `titleField: 'name'`, and `ListView`'s calendar branch floored the same two
bindings at `'start_date'` / `'end_date'` one layer down. `ObjectCalendar`
decides whether it has a usable configuration by asking whether a start-date
binding is PRESENT, so the fabrication short-circuited its own refusal screen —
which has existed all along and was simply unreachable from this route.
Both faces now forward only what the author declared. With no binding to
forward, the capability gate stops offering the Calendar toggle to views that
configured none, and a view forced onto the renderer reaches the refusal
screen instead of a plausible, fully wrong one.
Ruled on objectstack#13748 (director batch objectstack-ai#19, option A). The spec half —
cross-field validation of a half-written declaration — is objectstack#13817.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
* fix(plugin-view): stop inventing calendar bindings on the element route too
`generateViewSchema` runs when no host supplies `renderListView` — the authored
`object-view` element — so it bypasses `ListView` and carried its own copy of
the fabrication (`start_date` / `end_date` / `name`). Same defect, same ruling
(objectstack#13748: no invented field names either way); fixing only the console
route would have left this one producing the same wrong screen.
Also retargets `ObjectView.titleFieldConvergence.test.tsx`: its `calendar`
column pinned the `|| 'name'` floor this card deletes, and the seam count drops
from seven to six. What objectui#6557 owns is unchanged and still pinned.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
* chore(changeset): objectui#7029 — no invented calendar field names
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
---------
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@huangyiirene@hotlong
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Add Markdown component with GFM support and XSS protection - #19

Merged
hotlong merged 7 commits into
mainfrom
copilot/add-markdown-component
Jan 14, 2026
Merged

Add Markdown component with GFM support and XSS protection#19
hotlong merged 7 commits into
mainfrom
copilot/add-markdown-component

Conversation

CopilotAI commented Jan 14, 2026

Copy link
Copy Markdown
Contributor

Implementation Plan for Markdown Component

  • Explore repository structure and understand component architecture
  • Add markdown rendering library (react-markdown) as dependency
  • Create markdown UI component in src/ui/
  • Create markdown renderer in src/renderers/data-display/
  • Register markdown component in data-display index
  • Add tests for markdown component
  • Build and verify the implementation
  • Create example/demo to verify visual output
  • Run code review and address security concerns
  • Run security scan with CodeQL - No vulnerabilities found
  • Add JSDoc documentation following "Schema First" principle
  • Merge latest code from main branch

Summary

Successfully implemented a new Markdown component for Object UI with comprehensive JSDoc documentation and merged latest changes from main branch.

Changes in This Update

Added JSDoc Documentation

  • Added comprehensive JSDoc comments to MarkdownProps interface
  • Added detailed JSDoc to the markdown renderer component
  • Documentation follows "Schema First" principle for auto-generated docs
  • Includes usage examples and feature descriptions

Merged Main Branch

  • Successfully merged 133 commits from main branch
  • No conflicts encountered
  • All tests pass after merge
  • Build successful

Component Features

  • Full markdown rendering with GitHub Flavored Markdown support
  • XSS protection via rehype-sanitize
  • Dark mode support
  • Tailwind CSS prose styling
  • Comprehensive JSDoc documentation for API reference generation
Original prompt

新建一个makkdown的组件


💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.

CopilotAIand others added 3 commits January 14, 2026 00:05
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>
Co-authored-by: huangyiirene <7665279+huangyiirene@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR introduces a new Markdown component to Object UI, enabling schema-driven rendering of markdown content with GitHub Flavored Markdown support and XSS protection.

Changes:

  • Added markdown UI component with Tailwind prose styling and security hardening
  • Created markdown renderer component and registered it with ComponentRegistry
  • Added comprehensive test coverage and a working demo in the prototype application

Reviewed changes

Copilot reviewed 7 out of 8 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
packages/components/src/ui/markdown.tsxNew UI component wrapping react-markdown with Tailwind styling and security
packages/components/src/ui/index.tsExport statement for the new markdown component
packages/components/src/renderers/data-display/markdown.tsxRenderer component registering markdown with ComponentRegistry
packages/components/src/renderers/data-display/index.tsImport statement to include markdown renderer
packages/components/src/new-components.test.tsTest case verifying markdown component registration
packages/components/package.jsonAdded react-markdown, remark-gfm, and rehype-sanitize dependencies
examples/prototype/src/App.tsxDemo implementation showcasing markdown component features
Files not reviewed (1)
  • pnpm-lock.yaml: Language not supported

Comment on lines +7 to +10
export interface MarkdownProps {
content: string
className?: string
}

CopilotAIJan 14, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The MarkdownProps interface lacks JSDoc comments. According to Rule #3 ('Schema First' Mindset), every property in the Schema MUST have JSDoc to enable auto-generated documentation for the open-source community. Add JSDoc describing the purpose of 'content' and 'className' properties.

Copilot generated this review using guidance from repository custom instructions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added comprehensive JSDoc documentation to the MarkdownProps interface describing the purpose and supported features of each property. Documentation follows the "Schema First" principle to enable auto-generated API docs. (commit c31876c)

import { Markdown } from '@/ui';

ComponentRegistry.register('markdown',
({ schema, className, ...props }) => (

CopilotAIJan 14, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The renderer component function lacks JSDoc documentation. Add a JSDoc comment explaining that this is a Schema-driven renderer for markdown content, following the 'Schema First' principle outlined in Rule #3.

Copilot generated this review using guidance from repository custom instructions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added detailed JSDoc documentation to the markdown renderer component explaining its schema-driven architecture and usage. Includes example JSON configuration and lists all supported features. (commit c31876c)

CopilotAI changed the title [WIP] Add new markdown componentAdd Markdown component with GFM support and XSS protectionJan 14, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ All checks passed!

  • ✅ Type check passed
  • ✅ Tests passed
  • ✅ Lint check completed

@huangyiirene

Copy link
Copy Markdown
Collaborator

@copilot 从主分支之更新最新代码并修正代码冲突

CopilotAI commented Jan 14, 2026

Copy link
Copy Markdown
ContributorAuthor

@copilot 从主分支之更新最新代码并修正代码冲突

Successfully merged 133 commits from main branch. No conflicts encountered. All tests pass and build is successful. (commit ee033e8)

@github-actions

Copy link
Copy Markdown
Contributor

✅ All checks passed!

  • ✅ Type check passed
  • ✅ Tests passed
  • ✅ Lint check completed

@hotlong
hotlong marked this pull request as ready for review January 14, 2026 01:01
@hotlong
hotlong merged commit 57424b3 into mainJan 14, 2026
1 of 5 checks passed
os-sam pushed a commit that referenced this pull request Aug 31, 2026
…iews that declared none
A view carrying no `calendar:` block used to have a complete-looking calendar
config synthesized for it: `ObjectView` fabricated `startDateField: 'due_date'`
and `titleField: 'name'`, and `ListView`'s calendar branch floored the same two
bindings at `'start_date'` / `'end_date'` one layer down. `ObjectCalendar`
decides whether it has a usable configuration by asking whether a start-date
binding is PRESENT, so the fabrication short-circuited its own refusal screen —
which has existed all along and was simply unreachable from this route.
Both faces now forward only what the author declared. With no binding to
forward, the capability gate stops offering the Calendar toggle to views that
configured none, and a view forced onto the renderer reaches the refusal
screen instead of a plausible, fully wrong one.
Ruled on objectstack#13748 (director batch #19, option A). The spec half —
cross-field validation of a half-written declaration — is objectstack#13817.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Sep 1, 2026
…mes, so the refusal screen becomes reachable (objectstack-ai#7062)
* fix(app-shell,plugin-list): stop inventing calendar field names for views that declared none
A view carrying no `calendar:` block used to have a complete-looking calendar
config synthesized for it: `ObjectView` fabricated `startDateField: 'due_date'`
and `titleField: 'name'`, and `ListView`'s calendar branch floored the same two
bindings at `'start_date'` / `'end_date'` one layer down. `ObjectCalendar`
decides whether it has a usable configuration by asking whether a start-date
binding is PRESENT, so the fabrication short-circuited its own refusal screen —
which has existed all along and was simply unreachable from this route.
Both faces now forward only what the author declared. With no binding to
forward, the capability gate stops offering the Calendar toggle to views that
configured none, and a view forced onto the renderer reaches the refusal
screen instead of a plausible, fully wrong one.
Ruled on objectstack#13748 (director batch objectstack-ai#19, option A). The spec half —
cross-field validation of a half-written declaration — is objectstack#13817.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
* fix(plugin-view): stop inventing calendar bindings on the element route too
`generateViewSchema` runs when no host supplies `renderListView` — the authored
`object-view` element — so it bypasses `ListView` and carried its own copy of
the fabrication (`start_date` / `end_date` / `name`). Same defect, same ruling
(objectstack#13748: no invented field names either way); fixing only the console
route would have left this one producing the same wrong screen.
Also retargets `ObjectView.titleFieldConvergence.test.tsx`: its `calendar`
column pinned the `|| 'name'` floor this card deletes, and the seam count drops
from seven to six. What objectui#6557 owns is unchanged and still pinned.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
* chore(changeset): objectui#7029 — no invented calendar field names
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
---------
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@huangyiirene@hotlong