From 1879a1f77c488e39e4726056d7c1ccaecb7eac09 Mon Sep 17 00:00:00 2001 From: Bryan Frimin Date: Thu, 19 Mar 2026 22:12:37 +0100 Subject: [PATCH] Escape Markdown table cell values in compliance page template Pipe characters and newlines in dynamic values break Markdown table structure. Add a cell template function that escapes these characters. Signed-off-by: Bryan Frimin --- pkg/trust/compliance.md.tmpl | 10 +++++----- pkg/trust/compliance_page_service.go | 13 ++++++++++++- 2 files changed, 17 insertions(+), 6 deletions(-) diff --git a/pkg/trust/compliance.md.tmpl b/pkg/trust/compliance.md.tmpl index 1f649a0a2..e2727e441 100644 --- a/pkg/trust/compliance.md.tmpl +++ b/pkg/trust/compliance.md.tmpl @@ -12,29 +12,29 @@ | Title | Type | |-------|------| -{{ range .Documents }}| {{ .Title }} | {{ .Type }} | +{{ range .Documents }}| {{ cell .Title }} | {{ cell .Type }} | {{ end }}{{ end }}{{ if .Audits }} ## Audits | Name | Framework | Valid From | Valid Until | |------|-----------|------------|-------------| -{{ range .Audits }}| {{ .Name }} | {{ .Framework }} | {{ .ValidFrom }} | {{ .ValidUntil }} | +{{ range .Audits }}| {{ cell .Name }} | {{ cell .Framework }} | {{ .ValidFrom }} | {{ .ValidUntil }} | {{ end }}{{ end }}{{ if .Vendors }} ## Subprocessors | Name | Category | Countries | Website | |------|----------|-----------|---------| -{{ range .Vendors }}| {{ .Name }} | {{ .Category }} | {{ .Countries }} | {{ .Website }} | +{{ range .Vendors }}| {{ cell .Name }} | {{ cell .Category }} | {{ cell .Countries }} | {{ cell .Website }} | {{ end }}{{ end }}{{ if .References }} ## References | Name | Description | Website | |------|-------------|---------| -{{ range .References }}| {{ .Name }} | {{ .Description }} | {{ .Website }} | +{{ range .References }}| {{ cell .Name }} | {{ cell .Description }} | {{ cell .Website }} | {{ end }}{{ end }}{{ if .ExternalLinks }} ## External Links | Name | URL | |------|-----| -{{ range .ExternalLinks }}| {{ .Name }} | {{ .URL }} | +{{ range .ExternalLinks }}| {{ cell .Name }} | {{ cell .URL }} | {{ end }}{{ end }} \ No newline at end of file diff --git a/pkg/trust/compliance_page_service.go b/pkg/trust/compliance_page_service.go index 8d82427ff..9ba8720ae 100644 --- a/pkg/trust/compliance_page_service.go +++ b/pkg/trust/compliance_page_service.go @@ -31,7 +31,18 @@ import ( //go:embed compliance.md.tmpl var complianceTmplContent string -var complianceTmpl = template.Must(template.New("compliance").Parse(complianceTmplContent)) +var complianceTmpl = template.Must( + template.New("compliance"). + Funcs(template.FuncMap{ + "cell": func(s string) string { + s = strings.ReplaceAll(s, `|`, `\|`) + s = strings.ReplaceAll(s, "\n", " ") + s = strings.ReplaceAll(s, "\r", "") + return s + }, + }). + Parse(complianceTmplContent), +) type ( compliancePageData struct {