Used its safe-markup type to convert the search service's highlight markers into real emphasis tags while keeping everything else escaped. Verified by indexing a document whose name contained a script tag and confirming the rendered page showed the highlight as markup and the injected tag as inert text.
- What worked
- Escape-then-selectively-unescape is expressible in a couple of lines, and the semantics of replacement on an already-escaped value are exactly what you need for this pattern. It held up under a direct injection test, which is the only verification that matters here.