diff --git a/controllers/blog.go b/controllers/blog.go index 0b5a510..280686c 100644 --- a/controllers/blog.go +++ b/controllers/blog.go @@ -104,8 +104,9 @@ func CreateBlogPost(c *gin.Context) { return } // Create the blog post in the database - if db.Create(&data).Error != nil { - c.Status(http.StatusNotAcceptable) + err = db.Create(&data).Error + if err != nil { + c.JSON(http.StatusNotAcceptable, "{ \"error\": "+err.Error()+" }") } else { c.Status(http.StatusAccepted) } @@ -186,6 +187,7 @@ func GetBlogPostById(id string) *models.BlogPost { } func GetCommentsByContent(content string, url string) *[]models.Comment { + // This is used to make sure people don't paste the same thing over and over. var comments []models.Comment err := db.Model(&comments).Where("content like ? and associated_post like ?", "%"+content[1:]+"%", url).Scan(&comments).Error if err != nil { diff --git a/main.go b/main.go index fee5c9f..bee1d58 100644 --- a/main.go +++ b/main.go @@ -18,6 +18,8 @@ along with this program. If not, see .Rawley Fow */ import ( + "html/template" + "github.com/gin-gonic/gin" "gitlab.com/rawleyifowler/site-rework/bootstrap" ) @@ -28,6 +30,13 @@ var dsn string func main() { router = gin.Default() router.Use(gin.Recovery()) + // Create function map for templates that will unescape HTML from the database + // Credits to: https://h1z3y3.me/posts/go-html-template-script-unescape + funcMap := make(template.FuncMap) + funcMap["UnescapeHTML"] = func(s string) template.HTML { + return template.HTML(s) + } + router.SetFuncMap(funcMap) // This needs to change because of RCCTL in OpenBSD, not sure if you can use a ksh variable as path in Gin but i'll test router.LoadHTMLGlob("templates/*.tmpl") bootstrap.InitializeRoutes(router) diff --git a/templates/blog_post.tmpl b/templates/blog_post.tmpl index 0f026f2..ea419b8 100644 --- a/templates/blog_post.tmpl +++ b/templates/blog_post.tmpl @@ -1,7 +1,7 @@ {{ template "header.tmpl" . }}

{{ .Post.Title }}

-
{{ .Post.Content }}
+
{{ .Post.Content | UnescapeHTML }}

Comments

{{ range $comment := .Post.Comments }}