Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 20 additions & 0 deletions latte/cs/html-attributes.texy
Original file line number Diff line number Diff line change
Expand Up @@ -133,6 +133,26 @@ Stejně jako `class` přijímají i atributy `aria-` pole. To se zpracuje jako s
```


HTML dokument v atributu srcdoc .{data-version:3.2.0}
=====================================================

Atribut `srcdoc` elementu `<iframe>` obsahuje celý HTML dokument. Latte proto hodnotu escapuje dvakrát: nejprve jako HTML text a poté jako atribut. Řetězec se v rámu zobrazí jako prostý text a nemůže do něj vložit žádné značky:

```latte
<iframe srcdoc={$text}></iframe>
```

Pokud `$text` obsahuje `<b>Ahoj</b>`, vykreslí se:

```latte
<iframe srcdoc="&amp;lt;b&amp;gt;Ahoj&amp;lt;/b&amp;gt;"></iframe>
```

Chcete-li vložit důvěryhodné HTML, předejte ho jako objekt `Latte\Runtime\Html`. Jeho značky zůstanou zachovány a escapuje se jen jednou, jako atribut, takže stejný obsah se vykreslí jako `srcdoc="&lt;b&gt;Ahoj&lt;/b&gt;"`.

Předchozí verze vkládaly řetězce jako HTML. Takové hodnoty odhalí [migrační varování |develop#Migrační varování], pokud je hodnotou atributu jediný výraz `{...}`.


Typová kontrola
===============

Expand Down
20 changes: 20 additions & 0 deletions latte/en/html-attributes.texy
Original file line number Diff line number Diff line change
Expand Up @@ -133,6 +133,26 @@ Just like `class`, `aria-` attributes also accept an array. It is treated as a s
```


HTML Documents in srcdoc .{data-version:3.2.0}
==============================================

The `srcdoc` attribute of `<iframe>` contains a whole HTML document. Latte therefore escapes a value twice: first as HTML text and then as an attribute. A string is displayed in the frame as plain text and cannot inject any markup:

```latte
<iframe srcdoc={$text}></iframe>
```

If `$text` is `<b>Hi</b>`, it renders:

```latte
<iframe srcdoc="&amp;lt;b&amp;gt;Hi&amp;lt;/b&amp;gt;"></iframe>
```

To insert trusted HTML, pass it as a `Latte\Runtime\Html` object. Its markup is kept and escaped only once, as an attribute, so the same content renders as `srcdoc="&lt;b&gt;Hi&lt;/b&gt;"`.

Previous versions inserted strings as HTML. The [migration warnings |develop#Migration Warnings] point out such values when the entire attribute value is a single `{...}` expression.


Type Checking
=============

Expand Down
Loading