Browse files

[1.2.X] Fixed #15365 -- Added a warning to the `contrib.markup` docs …

…reminding users that the marked up output will not be escaped.

Backport of [15673] from trunk.

git-svn-id: bcc190cf-cafb-0310-a4f2-bffc1f526a37
  • Loading branch information...
1 parent 32ac8d9 commit a5f71e12643043da9bfdb554e0774c242f0f18b9 Gabriel Hurley committed Feb 28, 2011
Showing with 7 additions and 0 deletions.
  1. +7 −0 docs/ref/contrib/markup.txt
@@ -24,6 +24,13 @@ To activate these filters, add ``'django.contrib.markup'`` to your
For more documentation, read the source code in
+.. warning::
+ The output of markup filters is marked "safe" and will not be escaped when
+ rendered in a template. Always be careful to sanitize your inputs and make
+ sure you are not leaving yourself vulnerable to cross-site scripting or
+ other types of attacks.
.. _Textile:
.. _Markdown:
.. _reST (reStructured Text):

0 comments on commit a5f71e1

Please sign in to comment.