From b21e6d5552a691aabbde6c8dab6b6cf53cec2563 Mon Sep 17 00:00:00 2001 From: 123 Date: Fri, 12 Jun 2026 07:21:17 +0800 Subject: [PATCH 1/2] Address review: sanitize post HTML and extract serve.mjs - Run marked output through sanitize-html so AI-generated/untrusted post Markdown can't inject