xoofx / xoofx/markdig

Is there an Escape function so I can add user generated content to markdown and ensure it is escaped correctly

Open
#889 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

question
Dominant language
C#
Stars
5.3k
Forks
510
Avg merge
8d 5h
Merged PRs (30d)
5

Description

I'm working on writing some markdown from a system that allows user input. I want to include their text, but want to make sure their text doesn't get treated as markdown. I had AI create me a function, but was wondering if Markdig should have a built-in function for this kind of thing. Here is the function I'm using currently.

/// <summary>
/// Escapes user-entered text to prevent it from being interpreted as markdown.
/// This ensures user content is displayed as literal text rather than formatted markdown.
/// </summary>
/// <param name="text">The user-entered text to escape</param>
/// <returns>The escaped text safe for use in Markdown documents</returns>
public static string EscapeMarkdown(string text) {
    if (string.IsNullOrEmpty(text)) {
        return text;
    }

    // Dictionary of markdown special characters and their escaped equivalents
    var markdownChars = new Dictionary<char, string> {
        { '\\', @"\\" },  // Backslash must be first to avoid double-escaping
        { '*', @"\*" },   // Asterisk (bold/italic)
        { '_', @"\_" },   // Underscore (bold/italic)
        { '`', @"\`" },   // Backtick (code)
        { '#', @"\#" },   // Hash (headers)
        { '+', @"\+" },   // Plus (lists)
        { '-', @"\-" },   // Minus (lists, strikethrough)
        { '=', @"\=" },   // Equals (headers)
        { '|', @"\|" },   // Pipe (tables)
        { '{', @"\{" },   // Curly braces (various extensions)
        { '}', @"\}" },
        { '[', @"\[" },   // Square brackets (links, references)
        { ']', @"\]" },
        { '(', @"\(" },   // Parentheses (links)
        { ')', @"\)" },
        { '<', @"\<" },   // Angle brackets (HTML, autolinks)
        { '>', @"\>" },   // Greater than (blockquotes)
        { '!', @"\!" },   // Exclamation (images)
        { '~', @"\~" },   // Tilde (strikethrough)
        { '^', @"\^" },   // Caret (superscript in some dialects)
        { '.', @"\." },   // Period (can be part of lists when after numbers)
        { ':', @"\:" }    // Colon (definition lists in some dialects)
    };

    var result = new StringBuilder(text.Length * 2); // Pre-allocate for efficiency

    foreach (var c in text) {
        if (markdownChars.TryGetValue(c, out var escaped)) {
            result.Append(escaped);
        } else {
            result.Append(c);
        }
    }

    return result.ToString();
}

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No source file, test, or entry point is named. Start by reviewing the requested built-in escaping behavior and the proposed EscapeMarkdown function, then determine the intended Markdown dialect and supported characters; done should include a clearly defined API behavior and tests showing user text remains literal.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp
Domain
backend-api-design
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.