Skip to content

Filter block escapes input and | safe input together when a block mixes them #35

Description

@leehack

A filter block that mixes input-marked text with | safe input-marked text escapes all of it before the filter runs. So the safe part comes out escaped and the filter sees escaped text.

With x = JinjaString.user('<b>'):

{% filter upper %}{{ x }}{{ x | safe }}{% endfilter %}
  • Actual: &LT;B&GT;<B>
  • Expected: &lt;B&gt;<B>. The filter should see raw text, the marked part should be escaped once at output, and the safe part should stay raw.

Blocks that are all input or all safe work since #34. A mixed block needs the safe flag tracked per output part, not per value.

Accepted as a known limitation in #34.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingpriority:P3Useful cleanup or longer-term work

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions