fix: 修复代码块语法高亮丢失 + 语言标签注入 + 安全性增强

- 新增 cdnjs.cloudflare.com CSP 白名单,允许加载 highlight.js
- 消毒策略放行 span 元素,保留 highlight.js 高亮 class
- 详情页和新帖子页引入 highlight.js 库和 GitHub 主题
- 代码块语言选择器默认 text,支持 prev/next 循环切换语言
- 代码块语言标签注入兼容 data-language 和 code class 双来源
- 修复 utils.js defer 导致 common.js 执行时 getCSRFToken 未定义
This commit is contained in:
2026-05-28 15:21:44 +08:00
parent 91f2cbebc1
commit fe81c879b0
6 changed files with 305 additions and 348 deletions

View File

@ -1,184 +1,4 @@
{{template "layout/header.html" .}}
<style>
/* Tiptap 编辑器容器适配全高布局 */
#editor-container {
flex: 1;
overflow: hidden;
min-height: 0;
background: #fff;
}
/* Tiptap 编辑器核心样式 */
.tiptap {
padding: 16px 24px;
outline: none;
min-height: 100%;
font-size: 15px;
line-height: 1.7;
color: #24292f;
}
/* 段落间距 */
.tiptap p { margin: 0.5em 0; }
/* 标题 */
.tiptap h1 { margin: 1em 0 0.5em; font-size: 2em; font-weight: 700; }
.tiptap h2 { margin: 0.8em 0 0.4em; font-size: 1.5em; font-weight: 700; }
.tiptap h3 { margin: 0.6em 0 0.3em; font-size: 1.17em; font-weight: 700; }
/* 列表 */
.tiptap ul, .tiptap ol { padding-left: 1.5em; margin: 0.5em 0; }
.tiptap li { margin: 0.2em 0; }
.tiptap ul[data-type="taskList"] { list-style: none; padding-left: 0; }
.tiptap ul[data-type="taskList"] li { display: flex; align-items: flex-start; gap: 0.4em; }
.tiptap ul[data-type="taskList"] li > label { flex-shrink: 0; margin-top: 0.15em; }
/* 引用 */
.tiptap blockquote {
border-left: 3px solid #3498db;
padding-left: 1em;
margin: 0.5em 0;
color: #6b7280;
}
/* 代码块 */
.tiptap pre {
background: #1a2332;
color: #e2e8f0;
padding: 12px 16px;
border-radius: 6px;
font-size: 13px;
line-height: 1.5;
overflow-x: auto;
margin: 0.5em 0;
position: relative;
}
.tiptap pre code { background: transparent; padding: 0; color: inherit; font-size: inherit; white-space: pre; display: block; }
.tiptap code {
background: #f3f4f6;
padding: 2px 5px;
border-radius: 4px;
font-size: 0.9em;
font-family: 'SF Mono', 'Menlo', 'Monaco', monospace;
}
/* 代码块语言标签 */
.tiptap pre .code-lang-label {
position: absolute;
top: 0;
left: 0;
right: 0;
padding: 4px 16px;
font-size: 11px;
font-weight: 600;
color: #94a3b8;
background: #2c3e50;
border-radius: 6px 6px 0 0;
font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', 'Helvetica Neue', Arial, sans-serif;
pointer-events: none;
z-index: 1;
}
/* highlight.js 语法高亮主题 — 基于 One Dark适配 MetaLab 深蓝背景 */
.tiptap pre code .hljs-keyword,
.tiptap pre code .hljs-selector-tag,
.tiptap pre code .hljs-literal,
.tiptap pre code .hljs-section,
.tiptap pre code .hljs-link { color: #c792ea; }
.tiptap pre code .hljs-string,
.tiptap pre code .hljs-title,
.tiptap pre code .hljs-name,
.tiptap pre code .hljs-type,
.tiptap pre code .hljs-attribute,
.tiptap pre code .hljs-symbol,
.tiptap pre code .hljs-bullet,
.tiptap pre code .hljs-addition,
.tiptap pre code .hljs-variable,
.tiptap pre code .hljs-template-tag,
.tiptap pre code .hljs-template-variable { color: #c3e88d; }
.tiptap pre code .hljs-comment,
.tiptap pre code .hljs-quote,
.tiptap pre code .hljs-deletion,
.tiptap pre code .hljs-meta { color: #676e95; }
.tiptap pre code .hljs-number,
.tiptap pre code .hljs-regexp,
.tiptap pre code .hljs-built_in { color: #f78c6c; }
.tiptap pre code .hljs-function .hljs-title,
.tiptap pre code .hljs-doctag,
.tiptap pre code .hljs-formula { color: #82aaff; }
.tiptap pre code .hljs-tag,
.tiptap pre code .hljs-subst { color: #f07178; }
.tiptap pre code .hljs-emphasis { font-style: italic; }
.tiptap pre code .hljs-strong { font-weight: bold; }
.tiptap pre code .hljs-attr,
.tiptap pre code .hljs-selector-attr,
.tiptap pre code .hljs-selector-class,
.tiptap pre code .hljs-selector-id,
.tiptap pre code .hljs-selector-pseudo { color: #ffcb6b; }
/* 水平线 */
.tiptap hr { border: none; border-top: 1px solid #e5e7eb; margin: 1em 0; }
/* 图片 */
.tiptap img { max-width: 100%; height: auto; border-radius: 6px; }
/* 链接 */
.tiptap a { color: #3498db; text-decoration: underline; }
/* Placeholder */
.tiptap p.is-editor-empty:first-child::before {
content: attr(data-placeholder);
float: left;
color: #c4c4c4;
pointer-events: none;
height: 0;
}
/* 工具栏 */
.editor-toolbar {
display: flex;
gap: 2px;
padding: 6px 12px;
background: #fafafa;
border-bottom: 1px solid #e5e7eb;
flex-shrink: 0;
flex-wrap: wrap;
}
.editor-toolbar button {
display: inline-flex;
align-items: center;
justify-content: center;
width: 32px;
height: 30px;
border: 1px solid transparent;
border-radius: 4px;
background: transparent;
color: #374151;
font-size: 13px;
cursor: pointer;
transition: background 0.15s;
}
.editor-toolbar button:hover { background: #e5e7eb; }
.editor-toolbar button.is-active { background: #1a2332; color: #fff; }
.code-lang-select {
height: 30px;
padding: 0 6px;
border: 1px solid transparent;
border-radius: 4px;
background: transparent;
color: #374151;
font-size: 12px;
cursor: pointer;
font-family: inherit;
outline: none;
}
.code-lang-select:hover { border-color: #e5e7eb; }
.code-lang-select:focus { border-color: #3498db; }
.editor-toolbar .toolbar-divider {
width: 1px;
background: #e5e7eb;
margin: 3px 4px;
}
</style>
<body>
{{template "layout/nav.html" .}}

View File

@ -1,4 +1,5 @@
{{template "layout/header.html" .}}
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/highlight.js/11.11.0/styles/github-dark.min.css">
<body>
{{template "layout/nav.html" .}}
@ -45,18 +46,34 @@
{{template "layout/footer.html" .}}
<script src="https://cdnjs.cloudflare.com/ajax/libs/highlight.js/11.11.0/highlight.min.js"></script>
<script src="/static/js/common.js"></script>
<script>
// ---- 代码块语言标签注入 ----
// ---- 代码块语言标签注入 + 语法高亮 ----
(function() {
document.querySelectorAll('.post-detail-body pre').forEach(function(pre) {
// 从 pre 的 data-language 或 code 的 class 中获取语言
var lang = pre.getAttribute('data-language');
if (lang) {
var label = document.createElement('div');
label.className = 'code-lang-label';
label.textContent = lang;
pre.insertBefore(label, pre.firstChild);
pre.style.paddingTop = '32px';
if (!lang) {
var code = pre.querySelector('code');
if (code) {
var match = code.className.match(/language-(\w+)/);
if (match) lang = match[1];
}
}
lang = lang || 'text';
var label = document.createElement('div');
label.className = 'code-lang-label';
label.textContent = lang;
pre.insertBefore(label, pre.firstChild);
pre.style.paddingTop = '32px';
// 语法高亮
var code = pre.querySelector('code');
if (code && lang !== 'text') {
code.classList.add('language-' + lang);
hljs.highlightElement(code);
}
});
})();