/** * SVG sanitization for mermaid-rendered diagrams (markdown preview). The * diagrams come from untrusted markdown sources, so the emitted SVG is * re-sanitized before it reaches dangerouslySetInnerHTML — defense in depth * on top of mermaid's own `securityLevel: 'strict'` (labels escaped, click * directives inert) and `htmlLabels: false` (labels as real SVG ). * * What is stripped, and why: * - `foreignObject`: the only channel that can carry raw HTML inside an * SVG document — with it gone, a hostile label cannot smuggle an * /