Skip to content

Commit

Permalink
Fixed #15365 -- Added a warning to the contrib.markup docs remindin…
Browse files Browse the repository at this point in the history
…g users that the marked up output will not be escaped.

git-svn-id: http://code.djangoproject.com/svn/django/trunk@15673 bcc190cf-cafb-0310-a4f2-bffc1f526a37
  • Loading branch information
Gabriel Hurley committed Feb 28, 2011
1 parent c9db8cc commit 13838fb
Showing 1 changed file with 7 additions and 0 deletions.
7 changes: 7 additions & 0 deletions docs/ref/contrib/markup.txt
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,13 @@ To activate these filters, add ``'django.contrib.markup'`` to your
For more documentation, read the source code in
:file:`django/contrib/markup/templatetags/markup.py`.

.. warning::

The output of markup filters is marked "safe" and will not be escaped when
rendered in a template. Always be careful to sanitize your inputs and make
sure you are not leaving yourself vulnerable to cross-site scripting or
other types of attacks.

.. _Textile: http://en.wikipedia.org/wiki/Textile_%28markup_language%29
.. _Markdown: http://en.wikipedia.org/wiki/Markdown
.. _reST (reStructured Text): http://en.wikipedia.org/wiki/ReStructuredText
Expand Down

0 comments on commit 13838fb

Please sign in to comment.