Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've just been implementing a comment system, which allows limited subset of Markdown formatting. I decided to store both original document and the resulting html, which goes through escaping, markdown and htmlpurifier, which strips everything unwanted. When the comment is edited, user gets the original document and the html version is shown on the site. It would be safer to do the html when outputting, but I decided this way for better performance.


Definitely. Performance requirements do justify what you're suggesting. Preprocessing when possible is a great principle to follow.

The point is that you're keeping your original data around is the key part.


The thing here is that if something goes wrong and malicious code ends up in the db, I have to go through every comment and clean them vs. just changing the code which cleans them way out.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: