""" 前台公开"关于本站"页面。 不需要登录,匿名可访问。Markdown 在模板里渲染。 """ import re import markdown as _markdown from flask import Blueprint, render_template from applications.models import About bp = Blueprint('public_about', __name__, url_prefix='/site') def _get_about() -> About: """复用 model 的种子逻辑,避免空表时炸""" a = About.query.get(1) if a is None: from applications.extensions import db a = About(id=1, site_name='旺珂 · 导航') db.session.add(a) db.session.commit() return a @bp.get('/about') def about(): a = _get_about() html = _render_md(a.content_md) return render_template('public/about.html', about=a, content_html=html) _URL_RE = re.compile(r'(https?://[^\s)<>"\\]+|[\w.+-]+@[\w-]+\.[\w.-]+)') def _render_md(text: str) -> str: """Markdown → HTML;自动把裸链接/邮箱变可点;同时禁掉 script/iframe。""" if not text or not text.strip(): return '' html = _markdown.markdown( text, extensions=['fenced_code', 'tables', 'nl2br', 'sane_lists'], output_format='html5', ) # 防御:清掉