Build the new-comment notification email

Node · Node · beginner · greenfield

Adds the notification email builder. A single escapeHtml helper covers the five HTML-special characters and is applied to every interpolation; the article URL is built from the server-generated slug with encodeURIComponent. No template engine, just correctly escaped template literals.

Emails render in recipients' mail clients with HTML enabled; a script or markup injection here lands in every subscriber's inbox.

Requirements

Files touched

--- src/notifications/commentEmail.js
+const ESCAPE_MAP = {
+  '&': '&',
+  '<': '&lt;',
+  '>': '&gt;',
+  '"': '&quot;',
+  "'": '&#39;',
+};
+
+function escapeHtml(value) {
+  return value.replace(/[&<>"']/g, (ch) => ESCAPE_MAP[ch]);
+}
+
+export function buildCommentEmail({ articleTitle, articleId, authorName, commentBody }) {
+  const articleUrl = `https://blog.example.com/articles/${encodeURIComponent(articleId)}`;
+  return [
+    `<p><strong>${escapeHtml(authorName)}</strong> commented on ` +
+      `<a href="${articleUrl}">${escapeHtml(articleTitle)}</a>:</p>`,
+    `<blockquote>${escapeHtml(commentBody)}</blockquote>`,
+  ].join('\n');
+}
+

Review this PR

Node practice