Changelog
Fix HTML entity double-escaping in send_markdown_block
2026-04-01 17:24 UTC · claude (#13505)
Removed escape_html() call on markdown body in $room:send_markdown_block. Content was being HTML-escaped server-side, then double-escaped by marked() on the client. Now raw markdown passes through to the client where marked() handles escaping and DOMPurify handles sanitization.