Skip to content

Flowvault v1.3.0 — Markdown preview without the leaks

Choose a tag to compare

@flowdeskadmin flowdeskadmin released this 22 Apr 13:50
· 21 commits to master since this release

Markdown preview & syntax-highlighted code blocks

Flowvault v1.3 renders your notes as GitHub-flavored Markdown with
syntax-highlighted code blocks, via a new Edit / Preview / Split
toggle in the editor toolbar. The preview is locked down by default:
raw HTML is blocked, external images are click-to-load, and external
links strip referrers. The textarea is still the source of truth;
notes are still stored as plain Markdown text inside the same
fixed-size hidden-volume slots.

Highlights

  • GitHub-flavored Markdown — headings, lists, task lists
    (- [x] done), tables, blockquotes, strikethrough, autolinks.
  • Fenced code blocks with Prism highlighting for TypeScript,
    Rust, Go, Python, Bash, JSON, YAML, SQL, and every other common
    language — highlighting runs entirely in your browser, no remote
    theme or grammar fetch.
  • Edit / Preview / Split segmented toggle. Split appears on
    viewports >~900 px; narrower viewports fall back to Preview while
    still remembering your preference. Mode preference is persisted in
    localStorage, not in the encrypted blob — your 512 KiB slot stays
    for content.
  • Lazy-loaded renderer bundle (~90 KB gz) via next/dynamic.
    Users who live in Edit mode pay zero bundle cost for the feature.

Security-first defaults

  • Raw HTML is blocked. <script>, <iframe>, <img onerror=…>
    and friends render as literal text, not elements. There is no
    opt-in.
  • External images are click-to-load. Every ![](https://…) URL
    shows up as a placeholder with the exact URL and an explicit
    "Load image" button — so a malicious .fvault restore or a
    hostile collaborator can't silently phone home the moment you
    unlock the vault. Base64 data: images render immediately (no
    network request).
  • External links are hardened with target="_blank",
    rel="noopener noreferrer", and
    referrerPolicy="no-referrer". The destination site never learns
    which Flowvault URL or local file the click came from.
  • javascript: and other non-HTTP link schemes render as text, not
    as clickable links.

What didn't change

  • The wire format. Your vault bytes, .fvault backup format, and
    plaintext Markdown .zip export are identical to v1.2 — v1.3 is
    a pure rendering addition with zero migration.
  • The crypto. Same Argon2id (64 MiB / 3 iter) + AES-256-GCM +
    hidden-volume layout.
  • The server. Still sees only opaque ciphertext; rendering is 100%
    client-side, post-decryption.

Docs

Thanks to everyone who asked for Markdown rendering. Keeping it
lean and zero-third-party-request was the interesting design
problem — and the result is a preview you can trust to render a
vault full of untrusted content.