mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 18:05:11 +03:00
We allow fetching external data in CodeSamples into a MDX environment, so we have to be careful about preventing code execution. Current checks: - External data is inserted as a code block (via the AST, not direct string manipulation), so it is escaped. Added two new layers of checks: - Allow-list of organizations, currently set to Supabase-only - Only allow immutable commit references
40 lines
1.3 KiB
TypeScript
40 lines
1.3 KiB
TypeScript
import { type Root } from 'mdast'
|
|
import { fromMarkdown } from 'mdast-util-from-markdown'
|
|
import { gfmFromMarkdown, gfmToMarkdown } from 'mdast-util-gfm'
|
|
import { mdxFromMarkdown, mdxToMarkdown } from 'mdast-util-mdx'
|
|
import { toMarkdown } from 'mdast-util-to-markdown'
|
|
import { gfm } from 'micromark-extension-gfm'
|
|
import { mdxjs } from 'micromark-extension-mdxjs'
|
|
|
|
import remarkMkDocsAdmonition from '~/lib/mdx/plugins/remarkAdmonition'
|
|
import remarkPyMdownTabs from '~/lib/mdx/plugins/remarkTabs'
|
|
import { getGitHubFileContents } from '~/lib/octokit'
|
|
import { getGitHubFileContentsImmutableOnly } from '~/lib/octokit'
|
|
import { codeSampleRemark } from './CodeSample'
|
|
|
|
type Transformer = (ast: Root) => Root | Promise<Root>
|
|
|
|
export async function preprocessMdx<T>(mdx: string, transformers: Transformer[]) {
|
|
let mdast = fromMarkdown(mdx, {
|
|
mdastExtensions: [mdxFromMarkdown(), gfmFromMarkdown()],
|
|
extensions: [mdxjs(), gfm()],
|
|
})
|
|
|
|
for (const transform of transformers) {
|
|
mdast = await transform(mdast)
|
|
}
|
|
|
|
const output = toMarkdown(mdast, { extensions: [mdxToMarkdown(), gfmToMarkdown()] })
|
|
return output
|
|
}
|
|
|
|
export function preprocessMdxWithDefaults(mdx: string) {
|
|
return preprocessMdx(mdx, [
|
|
remarkMkDocsAdmonition(),
|
|
remarkPyMdownTabs(),
|
|
codeSampleRemark({
|
|
fetchFromGitHub: getGitHubFileContentsImmutableOnly,
|
|
}),
|
|
])
|
|
}
|