a2nr
8e89fde3c1
fix: docked editor panel height + quiz image parser + assets dir config
...
- fix(layout): editor-area docked mode sekarang height:70vh (sebelumnya
max-height:85vh tanpa height, menyebabkan tab Arduino/velxio menciut
ke 150px karena iframe tidak punya intrinsic height)
- fix(layout): tambah overflow:hidden pada velxio/flowchart/quiz panel
untuk mencegah nested scrollable flex collapse
- feat(quiz): parser image dari 'image:' directive dan markdown 
di question flashcard; konversi bare filename ke /assets/ path
- feat(assets): ASSETS_DIR derived dari CONTENT_DIR untuk support
custom content directory (bukan hardcoded 'assets')
- fix(quiz): QuizTab container gunakan flex:1+min-height:0 (bukan height:100%)
- chore: hapus placeholder examples/assets/put_your_image.here
2026-07-21 20:50:01 +07:00
a2nr
2a09ee77ab
feat(embed): add raw HTML embed fence with bleach sanitization
...
- Add embed markdown fence: user pastes raw embed HTML code
(from Canva/YouTube/Google Docs Share→Embed) into lesson markdown
and slide content. Backend sanitizes via bleach (whitelist
tags/attrs/styles) + checks iframe src against domain blacklist
(SSRF prevention). Frontend renders iframe directly — no lazy
action needed.
- Backend: _process_embed_embeds + _sanitize_embed_html in
lesson_service.py, applied to lesson_content, exercise,
lesson_info, and slide loop. Graceful fallback if tinycss2
missing (CSS unsanitized but tags/attrs still stripped).
- Tests: 9 pytest cases (Canva/YouTube HTML, script stripping,
onclick stripping, blocked domain, non-https iframe, empty,
unchanged, dangerous style).
- Frontend: remove renderEmbedEmbeds.ts + wire-up + .generic-embed
CSS (URL-only approach from earlier iteration, superseded).
Keep .embed-error CSS for error messages.
- Example: update test_slides.md with raw HTML Canva embed (slide)
+ YouTube embed (body).
- Deps: bleach>=6.0.0, tinycss2>=1.2.0 in requirements.txt.
- Docs: consolidate 4 plan files into docs/06-embed-content.md.
2026-07-19 15:39:38 +07:00