INNER CODE UNIT · Python
mermaid
mrwadams/stride-gpt · apps/web/main.py:842
def mermaid(code: str, height: int = 500) -> None:
# Escape the LLM-supplied code before embedding it in raw HTML; Mermaid.js
# reads textContent (which auto-decodes entities) so the diagram still
# renders, but injected <script>/<img onerror> payloads cannot execute.
safe_code = html.escape(code)
components.html(
f"""
<pre class="mermaid" style="height: {height}px;">
{safe_code}
</pre>
<script type="module">
import mermaid from 'https://cdn.jsdelivr.net/npm/mermaid@10/dist/mermaid.esm.min.mjs';
mermaid.initialize({{ startOnLoad: true }});
</script>
""",
height=height,
)