# A posted doc cannot run code (2026-09-28). design-dev's impeccable run found # raw HTML passing through Python-Markdown into a `|safe` render; operator # ruling: ESCAPE it. Found while fixing it: markdown link hrefs, where an # entity-encoded `javascript:` passes any scheme test that does not decode # it first. Every row is a change tests/test_items.py claims to forbid. # # NOT here, on purpose: the tab/CR/LF drop and the C0 trim in `_browser_href`. # Python 3.13's urlsplit, under `is_safe_href`, drops the same characters, so no # test can see them go. They stay as a statement of browser semantics, and are # not claimed as proven falsifiers. unit = "doc html" [[mutation]] label = "block-level raw HTML passes through (a