"""Turning what members type into HTML. `html=False` is the whole security model, and it is worth understanding rather than copying. With raw HTML disabled, markdown-it never passes a fragment of the input through untouched: it emits only the tags its own rules produce, and everything else is escaped as text. A `