Flowvault v1.3.0 — Markdown preview without the leaks
Markdown preview & syntax-highlighted code blocks
Flowvault v1.3 renders your notes as GitHub-flavored Markdown with
syntax-highlighted code blocks, via a new Edit / Preview / Split
toggle in the editor toolbar. The preview is locked down by default:
raw HTML is blocked, external images are click-to-load, and external
links strip referrers. The textarea is still the source of truth;
notes are still stored as plain Markdown text inside the same
fixed-size hidden-volume slots.
Highlights
- GitHub-flavored Markdown — headings, lists, task lists
(- [x] done), tables, blockquotes, strikethrough, autolinks. - Fenced code blocks with Prism highlighting for TypeScript,
Rust, Go, Python, Bash, JSON, YAML, SQL, and every other common
language — highlighting runs entirely in your browser, no remote
theme or grammar fetch. - Edit / Preview / Split segmented toggle. Split appears on
viewports >~900 px; narrower viewports fall back to Preview while
still remembering your preference. Mode preference is persisted in
localStorage, not in the encrypted blob — your 512 KiB slot stays
for content. - Lazy-loaded renderer bundle (~90 KB gz) via
next/dynamic.
Users who live in Edit mode pay zero bundle cost for the feature.
Security-first defaults
- Raw HTML is blocked.
<script>,<iframe>,<img onerror=…>
and friends render as literal text, not elements. There is no
opt-in. - External images are click-to-load. Every
URL
shows up as a placeholder with the exact URL and an explicit
"Load image" button — so a malicious.fvaultrestore or a
hostile collaborator can't silently phone home the moment you
unlock the vault. Base64data:images render immediately (no
network request). - External links are hardened with
target="_blank",
rel="noopener noreferrer", and
referrerPolicy="no-referrer". The destination site never learns
which Flowvault URL or local file the click came from. javascript:and other non-HTTP link schemes render as text, not
as clickable links.
What didn't change
- The wire format. Your vault bytes,
.fvaultbackup format, and
plaintext Markdown.zipexport are identical to v1.2 — v1.3 is
a pure rendering addition with zero migration. - The crypto. Same Argon2id (64 MiB / 3 iter) + AES-256-GCM +
hidden-volume layout. - The server. Still sees only opaque ciphertext; rendering is 100%
client-side, post-decryption.
Docs
- Deep dive: Markdown preview and syntax-highlighted code, without
the usual leaks — https://flowvault.flowdesk.tech/blog/markdown-preview-code-highlighting - Updated FAQ section: Markdown preview & syntax-highlighted code
blocks — https://flowvault.flowdesk.tech/faq
Thanks to everyone who asked for Markdown rendering. Keeping it
lean and zero-third-party-request was the interesting design
problem — and the result is a preview you can trust to render a
vault full of untrusted content.