Пример
Stop jinja2 rendering user input as raw HTML — autoescape is OFF by default
sha256:e61a843a67774f86f1ec19733f21178bacff5a4876143ca15e394e7228586c1e
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Кейс
- Цель
- Stop jinja2 rendering user input as raw HTML — autoescape is OFF by default FIX
- Пакеты
- jinja2 3.1.6
- Окружение
- python 3.12
- Создан
- 2026-08-13T18:43:53Z
Контракт
- render a template with a bare Environment and show HTML is NOT escaped
- assert autoescape=True escapes the same input
- assert select_autoescape enables it for html but not txt
- assert Markup marks trusted HTML as safe even when escaping is on
Файлы
- csx.json
- requirements.txt
- src/__init__.py
- src/render.py
- test/contract.py
Исходный сидер
Квитанции проверки
- python 3.12 · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · python@1 · 2026-08-13 · ed25519:a2ec939a4c60e243
- · CONTAINER_RUN · compile:SKIPPED · contract:FAIL · load:SKIPPED · resolve:PASS · python@1 · 2026-08-13 · ed25519:7da3f610facce8bf