mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-12 07:59:02 +02:00
* feat(aside): browser-driver contract, cookbook, research and fallback resolvers
{{ASIDE_SETUP}} (readiness probe + ten rules for driving the user's real browser), {{ASIDE_COOKBOOK}} (script shapes verified live against Aside CLI 1.26: one flow per aside repl script, CDP console hook before navigation, evidence lines, session-directory artifact handoff, GSTACK_STEP_OK sentinel), {{ASIDE_RESEARCH}} (research through aside exec, WebSearch when Aside is absent, knowledge otherwise) and {{BROWSE_FALLBACK}} (the fifteen-row Aside-step to $B-command table plus the rules that differ, so every browsing skill keeps working on gstack's own headless browser). test/aside-driver.test.ts pins the sentences and asserts every browsing skill carries the Aside block followed by the fallback; test/helpers/aside-available.ts is the shared live-Aside probe.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* feat(render): Aside-first local-HTML renderer with the bundled browser as fallback
lib/aside-render.ts serves the HTML's directory on loopback (Aside refuses file:// URLs), opens it with waitUntil load, prints through CDP Page.printToPDF so tagged output, outlines, header/footer templates and page numbers survive, emulates device metrics for sized screenshots, and writes in-page evaluations to files; when Aside is absent it runs the same spec through the browse daemon (newtab, load, js, pdf, screenshot, closetab) and reports ENGINE=aside|browse. bin/gstack-render.ts is the CLI skill templates call. lib/claude-bin.ts and lib/error-handling.ts become the canonical copies (browse/src re-exports them).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* refactor(browse): /browse drives Aside first, with the $B reference behind the fallback
Contract, cookbook, mode choice (aside repl by default, aside exec for reading), report format, the fallback section, and the full command reference carved on demand.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* refactor(qa): /qa and /qa-only drive Aside, fall back to $B
QA_METHODOLOGY runs every phase as Aside scripts (orient, explore, document, re-test, mobile viewport via CDP emulation, links via HEAD fetch); the authenticate phase is 'you are already signed in'; a 13th rule requires consent before mutating actions on non-local targets; the fallback section translates each step onto $B. The qa E2E tests run on whichever engine is present.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* refactor(design): design-review, design-consultation, design-shotgun, plan-design-review, design-html drive Aside
Design-system extraction is one script printing FONTS/COLORS/HEADINGS/TOUCH_TARGETS/NAV; competitor research confirms the exact URLs before opening them in the real browser and runs on the bundled browser when Aside is absent; design-html's viewport screenshots, sketches and comparison boards render through gstack-render.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* refactor(deploy): benchmark, canary, land-and-deploy Step 7, devex-review drive Aside
One aside repl script per page prints NAV/PAINT/LCP/RESOURCES/SCRIPTS/CSS/SUMMARY (benchmark), CONSOLE_ERRORS/NAV/TEXT + screenshot (canary, re-run every 60s), and the post-deploy check reads responseStatus from the navigation entry; each carries the $B fallback.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* feat(third-party-actions): Aside is the recommended driver; gstack's visible browser stays the fallback
The readiness probe is lifted from {{ASIDE_SETUP}} at gen time (byte-identity pinned) and rule 3 points at browse/SKILL.md for how to drive; the consent question offers Aside first and gstack's own visible browser (handoff/resume for sign-in) as the fallback, as v1.72 framed it.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* refactor(scrape): /scrape reads pages through Aside; the browser-skills runtime rides the fallback
Look-then-extract scripts build the JSON inside the page and print it between JSON_START/JSON_END; aside exec for fuzzy intents; on the $B fallback the browser-skills match/prototype flow and /skillify apply as before.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* refactor(make-pdf): print through Aside first, the bundled browser otherwise
asideClient.ts replaces the direct $B client with one render() call per PDF (the exact option mapping the browse pdf command had: paper, margins, header/footer/page numbers, tagged, outline, printBackground, preferCSSPageSize, Paged.js wait); the diagram pre-pass, oversized-image downscale and DOCX rasters each run as one render script with per-fence try/catch; exit 4 now means no browser is available and names both remedies; $P setup reports which engine it found. The e2e gates run on whichever engine is present, so the Linux lane exercises the fallback.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* refactor(diagram): the triplet is one gstack-render call
SVG, PNG and excalidraw from one invocation over the content-addressed bundle staged under /tmp/gstack-render; every diagram type gets an excalidraw export; gstack-render picks the engine and prints ENGINE=; the diagram E2E gates on either engine.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* feat(research): web research runs in Aside first, WebSearch second
The planning, review, design, security and investigate skills research through {{ASIDE_RESEARCH}}; WebSearch stays in allowed-tools as the fallback; testing.ts's bootstrap step follows; skeleton ceilings ratcheted for the research block.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* feat(setup,gen-skill-docs): prune renders of skills that no longer exist
setup gains _prune_stale_generated for every host tree and the doc generator removes gstack-* output dirs it did not write, so a skill removed from the source tree can never linger in an install.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* test: registries, budgets and suite reconciled for Aside-first with the $B fallback
Touchfiles + E2E tiers gain the Aside keys, coverage matrix and eval baselines updated, size budget re-baselined to parity-baseline-v1.80.0.0.json (the contract plus fallback ride in every browsing skill), parity ceilings ratcheted with measured values, LLM-judge prompts and the E2E fixtures speak Aside-first, browse-fallback.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* docs: Aside first, gstack browser fallback
README, BROWSER.md, docs/, CONTRIBUTING, CLAUDE.md, ARCHITECTURE, AGENTS.md, TODOS and the root router describe the one product story: Aside is the browser gstack drives first; the bundled headless browser is the automatic fallback (Linux, Windows, app closed) where cookie import, GStack Browser, pair-agent and browser-skills still apply.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* chore: regenerate SKILL.md docs, llms.txt, agents digest, ship goldens, context-budget fixture
bun run gen:skill-docs over the templates; goldens re-rendered; context-budget ceilings recaptured.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* v1.80.0.0: Aside is the browser gstack drives first; the bundled browser is the fallback
MINOR: new capability across ten skills, the renderer and research; nothing removed. CHANGELOG release summary + itemized changes; VERSION 1.80.0.0; package.json 1.80.0.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* docs(todos): file non-Claude host ownership-gate and version-heading pin follow-ups
Two follow-ups from the /plan-ceo-review + /plan-eng-review pass on merging
PR #2804 with main's v1.80.0.0 ownership gate: bring the Codex/Factory/
OpenCode/Cursor/Kiro copy loops and the stale-render prune under the
.gstack-owned marker rule, and a free test pinning that the CHANGELOG top
heading equals VERSION (the collision that git cannot see).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* fix: pre-landing review fixes for the Aside-first branch
Review army + adversarial passes (Claude and Codex) on the merged branch:
setup
- _prune_stale_generated scans the host dirs too (the generator already
removed the render before setup ran, so the host branch was dead), skips
symlinks in the render tree (rm -rf on a slash-terminated link empties its
target), removes a host symlink only when it resolves into gstack, cleans a
bannered real dir through _cleanup_weak_dir, recognizes frontmatter-renamed
skills, and logs through log. The always-run codex render passes every host
dir that may link to it.
- NEEDS_BUILD checks all three binaries (with $_EXE) and lib/ sources; the
browser hint and the bootstrap summary honor GSTACK_SKIP_ASIDE, treat a
requested skip as a request, and derive one skill list.
lib/aside-render.ts + bin/gstack-render.ts
- The loopback server carries a per-render secret path, checks containment on
the real path (symlink escapes are 403), and rejects malformed encoding.
- Inline eval results are one base64 line, so page text cannot forge
ASIDE_DIR= or the sentinel; the last ASIDE_DIR wins.
- runProc escalates SIGTERM to SIGKILL, bounds every wait, and clears every
timer (an uncleared one kept gstack-render alive after printing OK).
- renderTmpDir refuses a shared /tmp name owned by someone else; the work dir
and server are created inside try; goto's budget follows the render budget.
- probeAside classifies a present-but-failing CLI as ASIDE_NOT_RUNNING like
the skills' bash probe; render() retries on gstack's own browser when Aside
could not start or its private CDP bridge is gone (never on a page error
or a timeout of a running script); the CLI reports the engine that actually
rendered, exits 0 on --help, rejects non-numeric flags, documents
--wait-timeout, fences EVAL/PAGE_ERRORS as untrusted content, and names the
daemon's cookie-import JS lock remedy.
- The browse path passes --scale only when asked (a scale change rebuilds
the daemon context) and restores the viewport after a sized screenshot.
resolvers / templates
- The bash probe honors GSTACK_SKIP_ASIDE and has a perl deadline on stock
macOS; .local is no longer LOCAL (mDNS); same-origin filters compare parsed
origins; link status is HEAD-checked only on LOCAL targets; every
aside exec goes through the receipted _aside_exec prelude
({{ASIDE_EXEC_PRELUDE}}), including nine template blocks that called it
bare; the design sketch and diagram staging use private directories.
- The generator prunes only bannered renders and never a host whose
generation failed.
Docs, stale comments and dead code cleaned; goldens re-rendered; tests
updated and added for every behavior above.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* test: coverage for the render CLI, setup rebuild check, make-pdf exit codes, and prose $B spans
New free tests from the ship coverage audit: test/gstack-render-cli.test.ts
(argv guards, --help, output contract with a fake daemon, failure and
serve-root paths, no-browser case, prompt exit), test/setup-needs-build.test.ts
(every binary and source set flips NEEDS_BUILD, Windows suffixes),
make-pdf/test/cli-exit-codes.test.ts and setup-smoke.test.ts (error to exit
code mapping, runSetup stages, renderPdf's engine), and prose-span cases for
extractBrowseCommands in test/skill-parser.test.ts.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* docs: CHANGELOG and TODOS cover the review fixes (v1.81.0.0)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* docs: sync project docs with the v1.81.0.0 review fixes
BROWSER.md, ARCHITECTURE.md, CONTRIBUTING.md, README.md, CLAUDE.md,
docs/TESTING_INTERNALS.md and docs/PROJECT_STRUCTURE.md now describe the
shipped renderer and setup: the loopback render server's per-render secret
path and real-path containment, ENGINE= naming the engine that actually
rendered (mid-run retry on gstack's own browser), EVAL/PAGE_ERRORS fenced as
untrusted content, --wait-timeout and the CLI's argv guards, the receipted
_aside_exec prelude ({{ASIDE_EXEC_PRELUDE}} in the placeholder table), the
LOCAL host rule without .local, LOCAL-only HEAD checks in the links script,
GSTACK_SKIP_ASIDE across probe/renderer/setup, the ownership-gated
retired-skill prune, the widened NEEDS_BUILD check, and the new free tests
(gstack-render-cli, setup-prune-stale-generated, setup-browser-hint,
setup-needs-build, make-pdf cli-exit-codes and setup-smoke).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* docs: CHANGELOG states the precise mid-run retry rule
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* fix(test): skill-e2e-bws slices the $B setup block from the Browser fallback section
browse/SKILL.md no longer has '## SETUP' / '## Core QA Patterns' (Aside is the
primary driver; the $B block moved under 'Browser fallback'), so the gate test
sliced an empty block and handed the agent nothing to run. Anchor on
'### Find the `$B` binary' up to the next heading. 7/7 pass.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* fix(test): gate POSIX-only fixtures off Windows
windows-free-tests: the gstack-render CLI tests drive a shebang fake browse
that CreateProcess cannot exec, and two NEEDS_BUILD cases assert an execute
bit and a bare-name miss that MSYS bash does not have (test -x ignores mode
bits and resolves design -> design.exe). Those describes and cases now
self-skip on win32; argument guards, --help, the no-browser case, and every
other rebuild-check case still run there.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* fix(render): runProc waits for the exit code until the kill deadline; newtab retries once on a cold daemon
A process whose pipes have reached EOF is exiting, but runProc gave the exit
code only five seconds to arrive and then returned null, which run() reports
as a failed command. Under CI's six-shard load one such render failed with the
artifact already written. The SIGTERM/SIGKILL timers already bound the wait,
so the exit race now runs to the kill deadline.
The first CLI call auto-starts the browse daemon; on a cold start it can
answer 'Unable to connect' once while the server is still coming up. That
single case is retried after 1.5s; every other newtab failure is not.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* test(aside-render): warm the daemon before live fallback cases; failures name the render error
- Live fallback cases run 'goto about:blank' up to twice before asserting and
skip (never fail) when the daemon cannot come up.
- expectOk() puts r.error and the browse transcript into the assertion so a
failed render is diagnosable from the CI log.
- The argv-contract cases dump the fake's log on a miss.
- File default timeout is 30s: the subject is the CLI contract, not latency.
- Two cases pin the cold-daemon newtab retry and that other errors are not
retried.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* docs: CHANGELOG notes the cold-start tolerance of the bundled-browser renderer
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
---------
Co-authored-by: Sina <sdroid674+github@gmail.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
835 lines
34 KiB
TypeScript
835 lines
34 KiB
TypeScript
/**
|
||
* Diagram + image pre-pass. Runs between "read markdown" and render() in the
|
||
* orchestrator, and owns everything that needs the diagram-render bundle.
|
||
*
|
||
* markdown ─▶ extractDiagramFences() ──▶ render() (marked+sanitize+smarty)
|
||
* │ fences → placeholder tokens │
|
||
* │ ▼
|
||
* └─▶ renderFenceSlots() ───────────▶ substituteSlots(html, slots)
|
||
* one browser render per batch │
|
||
* error ⇒ diagnostic block ▼
|
||
* inlineLocalImages(html)
|
||
* data URIs, probe dims from bytes,
|
||
* downscale >2x content box @300dpi,
|
||
* remote warn / missing placeholder /
|
||
* --strict hard-fail
|
||
*
|
||
* Placeholders survive marked, the sanitizer, and smartypants because they are
|
||
* plain hyphenated lowercase tokens with no quotes or HTML. Slot HTML is run
|
||
* through the same sanitizer as user content before substitution (the bundle
|
||
* renders with securityLevel strict — the sanitizer is the second layer).
|
||
*
|
||
* Bundle calls are batched: one render per batch (Aside runs one script per `aside repl` process) and
|
||
* nothing survives it, so every consumer collects its calls, runs them in one
|
||
* script (`BundleRun`), and substitutes the results. A failed call is data
|
||
* (diagnostic block / warning), never an abort. Each PDF run gets a fresh
|
||
* bundle page and each fence a fresh mermaid.render id (eng-review D6.2).
|
||
*/
|
||
|
||
import * as fs from "node:fs";
|
||
import * as os from "node:os";
|
||
import * as path from "node:path";
|
||
import * as crypto from "node:crypto";
|
||
import { fileURLToPath } from "node:url";
|
||
|
||
import { render as renderHtml, renderTmpDir } from "../../lib/aside-render";
|
||
import { escapeHtml, sanitizeUntrustedHtml } from "./render";
|
||
import { imageDims } from "./image-size";
|
||
|
||
// ─── Types ────────────────────────────────────────────────────────────
|
||
|
||
export interface DiagramFence {
|
||
/** "mermaid" | "excalidraw" */
|
||
lang: string;
|
||
/** Fence body (the diagram source). */
|
||
source: string;
|
||
/** Optional title="..." from the fence info string (a11y label, D6.4). */
|
||
title?: string;
|
||
/** Optional page=landscape|portrait fence directive (image-policy override). */
|
||
page?: "landscape" | "portrait";
|
||
/** render=false → leave as a plain code block (escape hatch, D6.3). */
|
||
render: boolean;
|
||
/** Placeholder token substituted into the markdown. */
|
||
token: string;
|
||
/** 1-based ordinal among rendered fences (unique ids, aria fallback). */
|
||
ordinal: number;
|
||
}
|
||
|
||
export interface FenceExtraction {
|
||
markdown: string;
|
||
fences: DiagramFence[];
|
||
}
|
||
|
||
export interface PrepassWarnings {
|
||
warn: (msg: string) => void;
|
||
}
|
||
|
||
export interface PrepassImageOptions {
|
||
/** Directory of the source markdown — relative image paths resolve here. */
|
||
inputDir: string;
|
||
/** Hard-fail on missing/remote images instead of warn (D6.1). */
|
||
strict: boolean;
|
||
/** Remote images are left untouched when network is explicitly allowed. */
|
||
allowNetwork: boolean;
|
||
/** Physical content-box width in inches (page width minus margins). */
|
||
contentWidthIn: number;
|
||
warn: (msg: string) => void;
|
||
/** Bundle runner for print-resolution downscaling; null = inline at full size. */
|
||
run: BundleRun | null;
|
||
}
|
||
|
||
/** Print-resolution policy (eng-review D4): downscale rasters wider than
|
||
* 2 × contentWidth × 300dpi down to contentWidth × 300dpi. */
|
||
const PRINT_DPI = 300;
|
||
const DOWNSCALE_FACTOR = 2;
|
||
/** Per-image read ceiling — bounds memory before any policy runs. */
|
||
const MAX_IMAGE_BYTES = 64 * 1024 * 1024;
|
||
|
||
export class StrictModeError extends Error {
|
||
constructor(msg: string) {
|
||
super(msg);
|
||
this.name = "StrictModeError";
|
||
}
|
||
}
|
||
|
||
// ─── Fence extraction (pure) ──────────────────────────────────────────
|
||
|
||
const DIAGRAM_LANGS = new Set(["mermaid", "excalidraw"]);
|
||
|
||
/**
|
||
* Extract column-0 ```mermaid / ```excalidraw fences, replacing each with a
|
||
* unique placeholder token paragraph. Backtick and tilde fences, any length
|
||
* >= 3; closers must be at least as long as the opener (CommonMark). Fences
|
||
* with `render=false` are left untouched.
|
||
*
|
||
* Two deliberate conservatisms (red-team finding — the original version
|
||
* reconstructed fences at column 0 and restructured lists):
|
||
* - Non-diagram fences replay as their ORIGINAL raw lines, byte-for-byte
|
||
* (only a render=false flag is removed, in place, preserving indent).
|
||
* - INDENTED diagram fences (inside lists/quotes) are NOT extracted — a
|
||
* column-0 placeholder would split the list. They replay verbatim as code.
|
||
*/
|
||
export function extractDiagramFences(markdown: string): FenceExtraction {
|
||
const lines = markdown.split("\n");
|
||
const out: string[] = [];
|
||
const fences: DiagramFence[] = [];
|
||
const runId = crypto.randomBytes(4).toString("hex");
|
||
|
||
let i = 0;
|
||
let openFence: {
|
||
char: string; len: number; indent: number; info: string;
|
||
rawOpener: string; body: string[];
|
||
} | null = null;
|
||
let ordinal = 0;
|
||
|
||
while (i < lines.length) {
|
||
const line = lines[i];
|
||
|
||
if (openFence) {
|
||
const close = matchFenceLine(line);
|
||
if (close && close.char === openFence.char && close.len >= openFence.len && close.info === "") {
|
||
const info = parseInfoString(openFence.info);
|
||
if (DIAGRAM_LANGS.has(info.lang) && info.render && openFence.indent === 0) {
|
||
ordinal++;
|
||
const token = `gstack-diagram-slot-${runId}-${ordinal}`;
|
||
fences.push({
|
||
lang: info.lang,
|
||
source: openFence.body.join("\n"),
|
||
title: info.title,
|
||
page: info.page,
|
||
render: true,
|
||
token,
|
||
ordinal,
|
||
});
|
||
out.push("", token, "");
|
||
} else {
|
||
// Not extracted (other language, render=false, or indented): replay
|
||
// the ORIGINAL lines verbatim; only strip a render=false flag.
|
||
out.push(stripRenderFalse(openFence.rawOpener));
|
||
out.push(...openFence.body);
|
||
out.push(line);
|
||
}
|
||
openFence = null;
|
||
i++;
|
||
continue;
|
||
}
|
||
openFence.body.push(line);
|
||
i++;
|
||
continue;
|
||
}
|
||
|
||
const open = matchFenceLine(line);
|
||
if (open && open.info !== "") {
|
||
openFence = { ...open, rawOpener: line, body: [] };
|
||
i++;
|
||
continue;
|
||
}
|
||
if (open) {
|
||
// Anonymous fence (plain code block) — copy through to its closer so a
|
||
// ```mermaid example INSIDE a plain fence is never extracted.
|
||
out.push(line);
|
||
i++;
|
||
while (i < lines.length) {
|
||
const l = lines[i];
|
||
const close = matchFenceLine(l);
|
||
out.push(l);
|
||
i++;
|
||
if (close && close.char === open.char && close.len >= open.len && close.info === "") break;
|
||
}
|
||
continue;
|
||
}
|
||
|
||
out.push(line);
|
||
i++;
|
||
}
|
||
|
||
// Unclosed fence at EOF: replay verbatim (CommonMark treats it as code to EOF).
|
||
if (openFence) {
|
||
out.push(openFence.rawOpener);
|
||
out.push(...openFence.body);
|
||
}
|
||
|
||
return { markdown: out.join("\n"), fences };
|
||
}
|
||
|
||
function matchFenceLine(line: string): { char: string; len: number; indent: number; info: string } | null {
|
||
const m = line.match(/^( {0,3})(`{3,}|~{3,})\s*(.*)$/);
|
||
if (!m) return null;
|
||
return { indent: m[1].length, char: m[2][0], len: m[2].length, info: m[3].trim() };
|
||
}
|
||
|
||
/** Remove a render=false flag from a raw opener line, preserving everything else. */
|
||
function stripRenderFalse(rawOpener: string): string {
|
||
return rawOpener.replace(/\s*\brender\s*=\s*false\b/i, "");
|
||
}
|
||
|
||
/** Parse a fence info string: `mermaid`, `mermaid render=false`,
|
||
* `mermaid title="Auth flow"`, `mermaid page=landscape`. */
|
||
export function parseInfoString(info: string): {
|
||
lang: string; render: boolean; title?: string; page?: "landscape" | "portrait";
|
||
} {
|
||
const lang = (info.match(/^\S+/)?.[0] ?? "").toLowerCase();
|
||
const render = !/\brender\s*=\s*false\b/i.test(info);
|
||
const title = info.match(/\btitle\s*=\s*"([^"]*)"/i)?.[1]
|
||
?? info.match(/\btitle\s*=\s*'([^']*)'/i)?.[1];
|
||
const pageRaw = info.match(/\bpage\s*=\s*(landscape|portrait)\b/i)?.[1]?.toLowerCase();
|
||
const page = pageRaw === "landscape" || pageRaw === "portrait" ? pageRaw : undefined;
|
||
return { lang, render, title, page };
|
||
}
|
||
|
||
// ─── Slot substitution (pure) ─────────────────────────────────────────
|
||
|
||
/**
|
||
* Replace placeholder tokens in rendered HTML with their final slot HTML.
|
||
* marked wraps the bare token line in <p>…</p>; replace the wrapper too so
|
||
* the figure isn't nested inside a paragraph.
|
||
*/
|
||
export function substituteSlots(html: string, slots: Map<string, string>): string {
|
||
let s = html;
|
||
for (const [token, slotHtml] of slots) {
|
||
// Function replacement is load-bearing: slot HTML carries user/LLM-authored
|
||
// diagram label text, and string-form replace() expands $&, $', $` patterns
|
||
// inside it — a label containing "$'" would duplicate the document tail.
|
||
const wrapped = new RegExp(`<p>\\s*${token}\\s*</p>`, "g");
|
||
const replaced = s.replace(wrapped, () => slotHtml);
|
||
s = replaced !== s ? replaced : s.split(token).join(slotHtml);
|
||
}
|
||
return s;
|
||
}
|
||
|
||
/**
|
||
* Visible diagnostic block for a failed fence render — never silent raw code
|
||
* (eng-review: explicit error blocks). Sanitizer-safe: all dynamic content is
|
||
* HTML-escaped.
|
||
*/
|
||
export function buildDiagnosticBlock(fence: DiagramFence, errorMessage: string): string {
|
||
const excerpt = fence.source.split("\n").slice(0, 8).join("\n");
|
||
const truncated = fence.source.split("\n").length > 8 ? "\n…" : "";
|
||
return [
|
||
`<figure class="diagram diagram-error" role="img" aria-label="${escapeHtml(diagramLabel(fence))} (failed to render)">`,
|
||
`<figcaption class="diagram-error-title">Diagram failed to render (${escapeHtml(fence.lang)})</figcaption>`,
|
||
`<pre class="diagram-error-detail">${escapeHtml(errorMessage.trim())}\n\n${escapeHtml(excerpt + truncated)}</pre>`,
|
||
`</figure>`,
|
||
].join("\n");
|
||
}
|
||
|
||
/**
|
||
* Wrap a rendered SVG in an accessible figure (D6.4). The raw fence source is
|
||
* preserved base64-encoded in a data attribute — an HTML comment would need
|
||
* `--` escaping, which corrupts every mermaid arrow (`-->`) and breaks
|
||
* round-trip recovery.
|
||
*/
|
||
export function buildDiagramFigure(fence: DiagramFence, svg: string): string {
|
||
const label = diagramLabel(fence);
|
||
const cleanSvg = sanitizeUntrustedHtml(svg);
|
||
const captioned = fence.title
|
||
? `\n<figcaption class="diagram-caption">${escapeHtml(fence.title)}</figcaption>`
|
||
: "";
|
||
const pageAttr = fence.page ? ` data-gstack-page="${fence.page}"` : "";
|
||
const sourceB64 = Buffer.from(fence.source, "utf8").toString("base64");
|
||
return [
|
||
`<figure class="diagram" role="img" aria-label="${escapeHtml(label)}"${pageAttr}` +
|
||
` data-gstack-lang="${escapeHtml(fence.lang)}" data-gstack-source="${sourceB64}">`,
|
||
cleanSvg,
|
||
captioned,
|
||
`</figure>`,
|
||
].join("\n");
|
||
}
|
||
|
||
/** Recover the original fence source from a rendered figure (round-trip). */
|
||
export function decodeFigureSource(figureHtml: string): string | null {
|
||
const m = figureHtml.match(/\bdata-gstack-source="([A-Za-z0-9+/=]*)"/);
|
||
if (!m) return null;
|
||
try {
|
||
return Buffer.from(m[1], "base64").toString("utf8");
|
||
} catch {
|
||
return null;
|
||
}
|
||
}
|
||
|
||
function diagramLabel(fence: DiagramFence): string {
|
||
return fence.title ?? `diagram ${fence.ordinal}`;
|
||
}
|
||
|
||
// ─── Bundle runner (diagram-render page, driven through Aside or gstack's browser) ────────
|
||
|
||
export type BundleCall = { fn: string; args: unknown[] };
|
||
export type BundleResult =
|
||
| { ok: true; value: string }
|
||
| { ok: false; error: string };
|
||
/** Run bundle calls in order. Every call gets a result; failures are data. */
|
||
export type BundleRun = (calls: BundleCall[]) => Promise<BundleResult[]>;
|
||
|
||
const READY_TIMEOUT_MS = 20_000;
|
||
/** Aside caps a script at 120s (the browse path shares the budget); ~40 mermaid renders fit with room to spare. */
|
||
const CALLS_PER_SCRIPT = 40;
|
||
|
||
/**
|
||
* Build the runner. The bundle path resolves lazily on the first call so an
|
||
* image-only document never touches it; a missing bundle fails every call
|
||
* with the resolver's message instead of throwing.
|
||
*/
|
||
export function bundleRunner(opts: { bundlePath?: string; render?: typeof renderHtml } = {}): BundleRun {
|
||
const render = opts.render ?? renderHtml;
|
||
let bundlePath = opts.bundlePath;
|
||
return async (calls) => {
|
||
const results: BundleResult[] = [];
|
||
try {
|
||
if (calls.length > 0) bundlePath ??= resolveBundlePath();
|
||
for (let i = 0; i < calls.length; i += CALLS_PER_SCRIPT) {
|
||
results.push(...await runScript(bundlePath!, calls.slice(i, i + CALLS_PER_SCRIPT), render));
|
||
}
|
||
} catch (err: any) {
|
||
// Unresolvable/unreadable bundle, staging failure: fail what's left as data.
|
||
const error = firstLine(err?.message ?? String(err));
|
||
while (results.length < calls.length) results.push({ ok: false, error });
|
||
}
|
||
return results;
|
||
};
|
||
}
|
||
|
||
/**
|
||
* One render (an Aside script, or a browse tab): open the bundle, wait for #done, evaluate one expression
|
||
* per call, write each result to a file and read them back. The bundle copy
|
||
* and one JSON args file per call sit in a private dir served over loopback,
|
||
* so multi-MB payloads (data URIs, scene JSON) never ride argv; results are
|
||
* files too (never inline stdout) so SVG/PNG text survives intact.
|
||
*/
|
||
async function runScript(
|
||
bundlePath: string,
|
||
calls: BundleCall[],
|
||
render: typeof renderHtml,
|
||
): Promise<BundleResult[]> {
|
||
const dir = fs.mkdtempSync(path.join(renderTmpDir(), "make-pdf-diagrams-"));
|
||
try {
|
||
const bundle = path.join(dir, "diagram-render.html");
|
||
fs.copyFileSync(bundlePath, bundle, fs.constants.COPYFILE_FICLONE);
|
||
const steps = calls.map((call, i) => {
|
||
fs.writeFileSync(path.join(dir, `call-${i}.json`), JSON.stringify(call.args));
|
||
// try/catch INSIDE the expression: a throwing fence returns an ERR
|
||
// marker and the script keeps going for the other fences. The URL is
|
||
// resolved against location.href, not the document base: the bundle
|
||
// sets <base href="https://gstack-render.localhost/"> for excalidraw.
|
||
const expression =
|
||
`(async () => { try { const a = await (await fetch(new URL("call-${i}.json", location.href).href)).json(); ` +
|
||
`return "OK:" + await window[${JSON.stringify(call.fn)}](...a); } ` +
|
||
`catch (e) { return "ERR:" + String((e && e.message) || e); } })()`;
|
||
return { kind: "eval" as const, expression, out: path.join(dir, `result-${i}.txt`) };
|
||
});
|
||
const r = await render({
|
||
file: bundle,
|
||
serveRoot: dir,
|
||
waitFor: { selector: "#done", timeoutMs: READY_TIMEOUT_MS },
|
||
steps,
|
||
});
|
||
if (!r.ok) {
|
||
const error = `diagram renderer: ${firstLine(r.error ?? "unknown error")}`;
|
||
return calls.map(() => ({ ok: false, error }));
|
||
}
|
||
return calls.map((_, i) => {
|
||
const text = fs.readFileSync(path.join(dir, `result-${i}.txt`), "utf8");
|
||
if (text.startsWith("OK:")) return { ok: true, value: text.slice(3) };
|
||
if (text.startsWith("ERR:")) return { ok: false, error: text.slice(4) };
|
||
return { ok: false, error: `unexpected bundle result: ${text.slice(0, 200)}` };
|
||
});
|
||
} finally {
|
||
fs.rmSync(dir, { recursive: true, force: true });
|
||
}
|
||
}
|
||
|
||
/** Resolve dist/diagram-render.html: env override → repo-relative (dev) → global install. */
|
||
export function resolveBundlePath(env: NodeJS.ProcessEnv = process.env): string {
|
||
const candidates = [
|
||
env.GSTACK_DIAGRAM_BUNDLE,
|
||
// dev: make-pdf/src/* → repo root lib/. (In a compiled binary this is the
|
||
// virtual /$bunfs/root and simply never exists — harmless.)
|
||
path.resolve(import.meta.dir, "../../lib/diagram-render/dist/diagram-render.html"),
|
||
// compiled binary at <root>/make-pdf/dist/pdf → <root>/lib/… — same shape
|
||
// in the repo and in the ~/.claude/skills/gstack global install. argv[0]
|
||
// is the literal string "bun" in compiled binaries; execPath is real.
|
||
path.resolve(path.dirname(process.execPath), "../../lib/diagram-render/dist/diagram-render.html"),
|
||
path.join(os.homedir(), ".claude/skills/gstack/lib/diagram-render/dist/diagram-render.html"),
|
||
].filter((p): p is string => !!p);
|
||
for (const p of candidates) {
|
||
if (fs.existsSync(p)) return p;
|
||
}
|
||
throw new Error(
|
||
"diagram-render bundle not found. Tried:\n" +
|
||
candidates.map((c) => ` - ${c}`).join("\n") +
|
||
"\nRun `bun run build:diagram-render` (repo) or re-run ./setup (install).",
|
||
);
|
||
}
|
||
|
||
// ─── Fence rendering ──────────────────────────────────────────────────
|
||
|
||
/**
|
||
* Render every extracted fence to its slot HTML in one batch. A failed fence
|
||
* yields a visible diagnostic block; the others still render.
|
||
*/
|
||
export async function renderFenceSlots(
|
||
fences: DiagramFence[],
|
||
run: BundleRun,
|
||
warn: (msg: string) => void,
|
||
): Promise<Map<string, string>> {
|
||
const slots = new Map<string, string>();
|
||
const fail = (fence: DiagramFence, msg: string) => {
|
||
warn(`diagram ${fence.ordinal} (${fence.lang}) failed to render: ${firstLine(msg)}`);
|
||
slots.set(fence.token, buildDiagnosticBlock(fence, msg));
|
||
};
|
||
const todo: DiagramFence[] = [];
|
||
for (const fence of fences) {
|
||
if (fence.lang !== "mermaid") {
|
||
try {
|
||
JSON.parse(fence.source); // fail fast with a JSON diagnostic, not a bundle stack
|
||
} catch (err: any) {
|
||
fail(fence, err?.message ?? String(err));
|
||
continue;
|
||
}
|
||
}
|
||
todo.push(fence);
|
||
}
|
||
const results = await run(todo.map((f) => f.lang === "mermaid"
|
||
? { fn: "__renderMermaid", args: [`mermaid-fence-${f.ordinal}`, f.source] }
|
||
: { fn: "__excalidrawToSvg", args: [f.source] }));
|
||
todo.forEach((fence, i) => {
|
||
const r = results[i];
|
||
if (r.ok) slots.set(fence.token, buildDiagramFigure(fence, r.value));
|
||
else fail(fence, r.error);
|
||
});
|
||
return slots;
|
||
}
|
||
|
||
// ─── DOCX rasterization (eng-review D6.5, P8) ─────────────────────────
|
||
|
||
/**
|
||
* Replace inline diagram SVGs (and svg data-URI images) with PNG <img> tags
|
||
* for the DOCX export — Word's SVG support is unreliable, so the content-
|
||
* fidelity contract embeds rasters at 300dpi of the placed width (the
|
||
* content box). Diagnostic blocks keep their text form. Two passes: swap
|
||
* each target for a token while collecting its bundle call, run the batch,
|
||
* substitute results.
|
||
*/
|
||
export async function rasterizeDiagramFigures(
|
||
html: string,
|
||
run: BundleRun,
|
||
contentWidthIn: number,
|
||
warn: (msg: string) => void,
|
||
): Promise<string> {
|
||
const targetPx = Math.round(contentWidthIn * PRINT_DPI);
|
||
const runId = crypto.randomBytes(4).toString("hex");
|
||
const calls: BundleCall[] = [];
|
||
const pending: Array<{ token: string; onOk: (png: string) => string; onErr: (reason: string) => string }> = [];
|
||
const enqueue = (svgText: string, onOk: (png: string) => string, onErr: (reason: string) => string): string => {
|
||
const token = `gstack-raster-slot-${runId}-${calls.length}`;
|
||
calls.push({ fn: "__rasterize", args: [svgText, targetPx] });
|
||
pending.push({ token, onOk, onErr });
|
||
return token;
|
||
};
|
||
|
||
// 1. Rendered diagram figures → <img> with the figure's aria-label as alt.
|
||
let out = html.replace(
|
||
/<figure class="diagram"[^>]*>[\s\S]*?<\/figure>/gi,
|
||
(figure) => {
|
||
const svgMatch = figure.match(/<svg\b[\s\S]*<\/svg>/i);
|
||
if (!svgMatch) return figure;
|
||
const label = figure.match(/\baria-label\s*=\s*"([^"]*)"/i)?.[1] ?? "diagram";
|
||
return enqueue(
|
||
svgMatch[0],
|
||
(png) => `<p><img src="${png}" alt="${label}"></p>`,
|
||
(reason) => {
|
||
warn(`docx: diagram rasterization failed (${reason}); embedding source text instead`);
|
||
// The converter drops <figure>/<svg> entirely, so returning the figure
|
||
// would make the diagram vanish without a trace — the exact invisible
|
||
// failure the diagnostic contract forbids. Surface the source.
|
||
const source = decodeFigureSource(figure) ?? "(source unavailable)";
|
||
return [
|
||
`<p><strong>Diagram could not be rasterized for DOCX (${escapeHtml(reason)}) — source:</strong></p>`,
|
||
`<pre>${escapeHtml(source)}</pre>`,
|
||
].join("\n");
|
||
},
|
||
);
|
||
},
|
||
);
|
||
|
||
// 2. SVG data-URI images (inlined .svg files) → PNG.
|
||
out = out.replace(/<img\b[^>]*>/gi, (tag) => {
|
||
const m = tag.match(SRC_RE);
|
||
const src = m?.[2] ?? m?.[3] ?? "";
|
||
if (!src.startsWith("data:image/svg+xml")) return tag;
|
||
const svgText = Buffer.from(src.slice(src.indexOf(",") + 1), "base64").toString("utf8");
|
||
return enqueue(
|
||
svgText,
|
||
// Function replacement: data URIs can contain $-patterns.
|
||
(png) => tag.replace(SRC_RE, () => `src="${png}"`),
|
||
(reason) => {
|
||
warn(`docx: svg image rasterization failed (${reason})`);
|
||
return tag;
|
||
},
|
||
);
|
||
});
|
||
|
||
if (calls.length === 0) return out;
|
||
const results = await run(calls);
|
||
pending.forEach((p, i) => {
|
||
const r = results[i];
|
||
// split/join, not replace(): the replacement carries user content.
|
||
out = out.split(p.token).join(r.ok ? p.onOk(r.value) : p.onErr(firstLine(r.error)));
|
||
});
|
||
return out;
|
||
}
|
||
|
||
/**
|
||
* Diagnostic figures → plain <p>/<pre> for the DOCX converter, which drops
|
||
* <figure> elements it can't map. An invisible error is the one thing the
|
||
* diagnostic contract forbids. Pure — no render tab needed.
|
||
*/
|
||
export function convertDiagnosticsForDocx(html: string): string {
|
||
return html.replace(
|
||
/<figure class="diagram diagram-error"[^>]*>([\s\S]*?)<\/figure>/gi,
|
||
(_full, body: string) => {
|
||
const title = body.match(/<figcaption[^>]*>([\s\S]*?)<\/figcaption>/i)?.[1] ?? "Diagram failed to render";
|
||
const detail = body.match(/<pre[^>]*>([\s\S]*?)<\/pre>/i)?.[1] ?? "";
|
||
return `<p><strong>${title}</strong></p>\n<pre>${detail}</pre>`;
|
||
},
|
||
);
|
||
}
|
||
|
||
// ─── Image inlining (eng-review D1 + D4 + D6.1) ───────────────────────
|
||
|
||
const IMG_TAG_RE = /<img\b[^>]*>/gi;
|
||
const SRC_RE = /\bsrc\s*=\s*("([^"]*)"|'([^']*)')/i;
|
||
|
||
/**
|
||
* Inline every local <img> as a data URI, probe intrinsic dimensions from the
|
||
* bytes, and annotate the tag with data-gstack-px-width/-height for the width
|
||
* policy. Oversized rasters are downscaled to print resolution via the bundle
|
||
* tab. Missing files become visible placeholders (or throw under --strict);
|
||
* remote URLs warn (offline posture) unless --allow-network.
|
||
*/
|
||
export async function inlineLocalImages(html: string, opts: PrepassImageOptions): Promise<string> {
|
||
const maxPx = Math.round(opts.contentWidthIn * PRINT_DPI * DOWNSCALE_FACTOR);
|
||
const targetPx = Math.round(opts.contentWidthIn * PRINT_DPI);
|
||
// An image referenced N times is read/probed/downscaled once; the same data
|
||
// URI string is reused (also dedupes memory until the final join).
|
||
const memo = new Map<string, { dataUri: string; attrs: string }>();
|
||
// Oversized rasters get a token src in this pass and their downscaled bytes
|
||
// in the second — one bundle batch for the whole document.
|
||
const runId = crypto.randomBytes(4).toString("hex");
|
||
const downscales: Array<{
|
||
token: string; src: string; name: string; buf: Buffer; mime: string;
|
||
dims: { width: number; height: number };
|
||
}> = [];
|
||
|
||
const out = html.replace(IMG_TAG_RE, (tag) => {
|
||
const srcMatch = tag.match(SRC_RE);
|
||
if (!srcMatch) return tag;
|
||
const src = srcMatch[2] ?? srcMatch[3] ?? "";
|
||
|
||
if (src.startsWith("data:")) return annotateFromDataUri(tag, src);
|
||
|
||
// Windows drive-letter paths (C:/x.png, C:\x.png) look like single-letter
|
||
// URL schemes — they are local paths, not URLs.
|
||
const isDrivePath = /^[a-zA-Z]:[\\/]/.test(src);
|
||
|
||
if (!isDrivePath && /^[a-z][a-z0-9+.-]*:/i.test(src)) {
|
||
// Absolute URL with a scheme (http, https, file, …)
|
||
if (opts.allowNetwork && /^https?:/i.test(src)) return tag;
|
||
if (/^https?:/i.test(src)) {
|
||
const msg = `remote image blocked (offline posture): ${src}`;
|
||
if (opts.strict) throw new StrictModeError(msg + " — re-run without --strict or pass --allow-network");
|
||
opts.warn(msg);
|
||
// Leaving the tag would make Chromium fetch it at print time anyway —
|
||
// the warn would be a lie. Replace with a visible placeholder.
|
||
return buildBlockedRemotePlaceholder(src);
|
||
}
|
||
// file:// and friends fall through to the local path branch
|
||
if (!src.startsWith("file:")) return tag;
|
||
}
|
||
|
||
// decodeURIComponent throws on malformed escapes (foo%zz.png) — a broken
|
||
// URL must degrade to the missing-image path, not crash the run.
|
||
let decodedSrc = src;
|
||
try {
|
||
decodedSrc = decodeURIComponent(src);
|
||
} catch { /* keep raw src */ }
|
||
|
||
const filePath = src.startsWith("file:")
|
||
? fileURLToPath(src)
|
||
: isDrivePath
|
||
? path.resolve(src)
|
||
: path.resolve(opts.inputDir, decodedSrc);
|
||
|
||
const cached = memo.get(filePath);
|
||
if (cached !== undefined) return rewriteImgTag(tag, cached);
|
||
|
||
if (!fs.existsSync(filePath)) {
|
||
const msg = `image not found: ${src} (resolved to ${filePath})`;
|
||
if (opts.strict) throw new StrictModeError(msg);
|
||
opts.warn(msg);
|
||
return buildMissingImagePlaceholder(src);
|
||
}
|
||
|
||
// Out-of-tree reads are legal (local CLI semantics — like pandoc) but
|
||
// never silent: an agent PDF-ing untrusted markdown should not quietly
|
||
// embed ~/.ssh/config into a shareable document. --strict makes it fatal.
|
||
// Compare REAL paths — a symlink inside the input dir pointing outside
|
||
// would otherwise pass a string-prefix check (Codex adversarial finding).
|
||
// Runs after the existence check: realpath of a missing file can't
|
||
// resolve, and on macOS /var vs /private/var would false-positive.
|
||
const inputRoot = safeRealpath(path.resolve(opts.inputDir)) + path.sep;
|
||
const realFilePath = safeRealpath(filePath);
|
||
if (!realFilePath.startsWith(inputRoot)) {
|
||
const msg = `image resolves OUTSIDE the input directory: ${src} → ${realFilePath}`;
|
||
if (opts.strict) throw new StrictModeError(msg + " — move it under the markdown's directory or drop --strict");
|
||
opts.warn(msg);
|
||
}
|
||
|
||
// Bound the read BEFORE reading: a markdown image pointing at a special
|
||
// file (fifo, device) would hang readFileSync, and a multi-GB file would
|
||
// exhaust memory before any policy ran.
|
||
let stat: fs.Stats;
|
||
try {
|
||
stat = fs.statSync(filePath);
|
||
} catch {
|
||
opts.warn(`image unreadable: ${src}`);
|
||
return buildMissingImagePlaceholder(src);
|
||
}
|
||
if (!stat.isFile()) {
|
||
const msg = `image is not a regular file: ${src}`;
|
||
if (opts.strict) throw new StrictModeError(msg);
|
||
opts.warn(msg);
|
||
return buildMissingImagePlaceholder(src);
|
||
}
|
||
if (stat.size > MAX_IMAGE_BYTES) {
|
||
const msg = `image exceeds ${Math.round(MAX_IMAGE_BYTES / 1024 / 1024)}MB cap: ${src} (${Math.round(stat.size / 1024 / 1024)}MB)`;
|
||
if (opts.strict) throw new StrictModeError(msg);
|
||
opts.warn(msg);
|
||
return buildMissingImagePlaceholder(src);
|
||
}
|
||
|
||
const buf = fs.readFileSync(filePath);
|
||
const dims = imageDims(buf);
|
||
const mime = dims?.mime ?? mimeFromExtension(filePath);
|
||
|
||
// Print-resolution normalization (D4): rasters only — SVG scales free.
|
||
if (dims && mime !== "image/svg+xml" && dims.width > maxPx && opts.run) {
|
||
const token = `gstack-downscale-slot-${runId}-${downscales.length}`;
|
||
downscales.push({ token, src, name: path.basename(filePath), buf, mime, dims });
|
||
memo.set(filePath, { dataUri: token, attrs: "" });
|
||
return rewriteImgTag(tag, memo.get(filePath)!);
|
||
}
|
||
|
||
memo.set(filePath, inlineEntry(buf, mime, dims));
|
||
return rewriteImgTag(tag, memo.get(filePath)!);
|
||
});
|
||
|
||
if (downscales.length === 0) return out;
|
||
const results = await opts.run!(downscales.map((d) => ({
|
||
fn: "__downscaleRaster",
|
||
args: [`data:${d.mime};base64,${d.buf.toString("base64")}`, targetPx, d.mime],
|
||
})));
|
||
const byToken = new Map<string, { dataUri: string; attrs: string }>();
|
||
downscales.forEach((d, i) => {
|
||
const r = results[i];
|
||
if (r.ok) {
|
||
opts.warn(
|
||
`downscaled ${d.name} ${d.dims.width}px → ${targetPx}px ` +
|
||
`(print is ${PRINT_DPI}dpi; original exceeds ${maxPx}px content-box ceiling)`,
|
||
);
|
||
const height = Math.round((d.dims.height * targetPx) / d.dims.width);
|
||
byToken.set(d.token, { dataUri: r.value, attrs: dimAttrs({ width: targetPx, height }) });
|
||
} else {
|
||
opts.warn(`downscale failed for ${d.src}, inlining at full size: ${firstLine(r.error)}`);
|
||
byToken.set(d.token, inlineEntry(d.buf, d.mime, d.dims));
|
||
}
|
||
});
|
||
return out.replace(IMG_TAG_RE, (tag) => {
|
||
const entry = byToken.get(tag.match(SRC_RE)?.[2] ?? "");
|
||
return entry ? rewriteImgTag(tag, entry) : tag;
|
||
});
|
||
}
|
||
|
||
function inlineEntry(buf: Buffer, mime: string, dims: { width: number; height: number } | null): { dataUri: string; attrs: string } {
|
||
return { dataUri: `data:${mime};base64,${buf.toString("base64")}`, attrs: dims ? dimAttrs(dims) : "" };
|
||
}
|
||
|
||
function dimAttrs(dims: { width: number; height: number }): string {
|
||
return ` data-gstack-px-width="${Math.round(dims.width)}" data-gstack-px-height="${Math.round(dims.height)}"`;
|
||
}
|
||
|
||
/** Apply a memoized inline result to an img tag. */
|
||
function rewriteImgTag(tag: string, entry: { dataUri: string; attrs: string }): string {
|
||
// Function replacement: data URIs are user-content-derived; string-form
|
||
// replace() would expand $-patterns inside them.
|
||
let out = tag.replace(SRC_RE, () => `src="${entry.dataUri}"`);
|
||
if (entry.attrs) out = out.replace(/^<img\b/i, () => `<img${entry.attrs}`);
|
||
return out;
|
||
}
|
||
|
||
function annotateFromDataUri(tag: string, src: string): string {
|
||
try {
|
||
const b64 = src.slice(src.indexOf(",") + 1);
|
||
const head = Buffer.from(b64.slice(0, 8192), "base64");
|
||
const dims = imageDims(head);
|
||
if (!dims) return tag;
|
||
return tag.replace(
|
||
/^<img\b/i,
|
||
`<img data-gstack-px-width="${Math.round(dims.width)}" data-gstack-px-height="${Math.round(dims.height)}"`,
|
||
);
|
||
} catch {
|
||
return tag;
|
||
}
|
||
}
|
||
|
||
function buildMissingImagePlaceholder(src: string): string {
|
||
return (
|
||
`<span class="image-missing" role="img" aria-label="missing image">` +
|
||
`[missing image: ${escapeHtml(src)}]</span>`
|
||
);
|
||
}
|
||
|
||
function buildBlockedRemotePlaceholder(src: string): string {
|
||
return (
|
||
`<span class="image-missing" role="img" aria-label="remote image blocked">` +
|
||
`[remote image blocked (use --allow-network): ${escapeHtml(src)}]</span>`
|
||
);
|
||
}
|
||
|
||
/** realpath that degrades to the input path when resolution fails. */
|
||
function safeRealpath(p: string): string {
|
||
try {
|
||
return fs.realpathSync(p);
|
||
} catch {
|
||
return p;
|
||
}
|
||
}
|
||
|
||
function mimeFromExtension(p: string): string {
|
||
switch (path.extname(p).toLowerCase()) {
|
||
case ".png": return "image/png";
|
||
case ".jpg":
|
||
case ".jpeg": return "image/jpeg";
|
||
case ".gif": return "image/gif";
|
||
case ".webp": return "image/webp";
|
||
case ".svg": return "image/svg+xml";
|
||
default: return "application/octet-stream";
|
||
}
|
||
}
|
||
|
||
// ─── Content-box math ─────────────────────────────────────────────────
|
||
|
||
const PAGE_WIDTHS_IN: Record<string, number> = {
|
||
letter: 8.5,
|
||
a4: 8.27,
|
||
legal: 8.5,
|
||
tabloid: 11,
|
||
};
|
||
|
||
/** Parse a CSS dimension ("1in" | "72pt" | "25mm" | "2.54cm") to inches. */
|
||
export function dimToInches(dim: string | undefined, fallbackIn: number): number {
|
||
if (!dim) return fallbackIn;
|
||
const m = dim.trim().match(/^([0-9.]+)\s*(in|pt|cm|mm|px)?$/i);
|
||
if (!m) return fallbackIn;
|
||
const v = parseFloat(m[1]);
|
||
switch ((m[2] ?? "in").toLowerCase()) {
|
||
case "in": return v;
|
||
case "pt": return v / 72;
|
||
case "cm": return v / 2.54;
|
||
case "mm": return v / 25.4;
|
||
case "px": return v / 96;
|
||
default: return fallbackIn;
|
||
}
|
||
}
|
||
|
||
export function contentWidthInches(opts: {
|
||
pageSize?: string;
|
||
margins?: string;
|
||
marginLeft?: string;
|
||
marginRight?: string;
|
||
}): number {
|
||
const pageW = PAGE_WIDTHS_IN[opts.pageSize ?? "letter"] ?? 8.5;
|
||
const left = dimToInches(opts.marginLeft ?? opts.margins, 1);
|
||
const right = dimToInches(opts.marginRight ?? opts.margins, 1);
|
||
return Math.max(1, pageW - left - right);
|
||
}
|
||
|
||
const PAGE_HEIGHTS_IN: Record<string, number> = {
|
||
letter: 11,
|
||
a4: 11.69,
|
||
legal: 14,
|
||
tabloid: 17,
|
||
};
|
||
|
||
/**
|
||
* Content box of the rotated (landscape) named page: portrait page HEIGHT
|
||
* becomes the landscape width; portrait WIDTH becomes the landscape height.
|
||
* Used by image-policy to vertically center promoted blocks.
|
||
*/
|
||
export function landscapeContentBox(opts: {
|
||
pageSize?: string;
|
||
margins?: string;
|
||
marginLeft?: string;
|
||
marginRight?: string;
|
||
marginTop?: string;
|
||
marginBottom?: string;
|
||
}): { contentWIn: number; contentHIn: number } {
|
||
const size = opts.pageSize ?? "letter";
|
||
const pageH = PAGE_HEIGHTS_IN[size] ?? 11;
|
||
const pageW = PAGE_WIDTHS_IN[size] ?? 8.5;
|
||
const left = dimToInches(opts.marginLeft ?? opts.margins, 1);
|
||
const right = dimToInches(opts.marginRight ?? opts.margins, 1);
|
||
const top = dimToInches(opts.marginTop ?? opts.margins, 1);
|
||
const bottom = dimToInches(opts.marginBottom ?? opts.margins, 1);
|
||
return {
|
||
contentWIn: Math.max(1, pageH - left - right),
|
||
contentHIn: Math.max(1, pageW - top - bottom),
|
||
};
|
||
}
|
||
|
||
// ─── tiny helpers ─────────────────────────────────────────────────────
|
||
// escapeHtml is imported from ./render — single definition, no drift.
|
||
|
||
function firstLine(s: string): string {
|
||
return s.split("\n")[0].slice(0, 200);
|
||
}
|