md2star.gui_server module
md2star local GUI server — Overleaf-style Markdown editor with live PDF preview.
Launches a localhost-only HTTP server that fronts the existing
md2star CLI: the browser sends Markdown + a small JSON options blob;
the server invokes _convert(fmt, ...) from md2star.cli against
a temp file and streams the resulting bytes back. The frontend renders
the PDF result inline via PDF.js (no DOCX/PPTX rendering in the browser
— those formats are simply offered as a download).
Endpoints
GET /→index.html(shipped undermd2star/data/gui/).GET /app.js→ the frontend ES module.GET /favicon.svg→ tiny inline SVG, no network calls.POST /render→ run the converter, stream back the bytes.POST /shutdown→ clean process exit (used by the in-page“Quit server” button so users do not have to find the terminal).
The server binds to 127.0.0.1 only (no LAN exposure) and uses
ThreadingHTTPServer so a slow /render does not block fast
/preview reads. There is no auth and no sandbox — it is intended
to run on the same machine as the user invoking it, just like Jupyter
or Vite’s dev server.
Security note
The only untrusted input is the /fs/* path a browser sends. Every such
path is funnelled through _safe_within_root(), which rejects ..
segments, absolute paths and symlink escapes so a request can never read or
write outside the single folder root the user opened. That confinement is
unit-tested in tests/test_gui_security.py.