Your skill will accomplish what the force of many cannot |
|
PerlMonks |
comment on |
( [id://3333]=superdoc: print w/replies, xml ) | Need Help?? |
I quite like HTML::Template's and HTML::Template::Compiled's default_escape options.
They take care that any variable in the template is escaped unless specified otherwise. That's nice if you forget to escape your variables (and still don't like XSS). Is there such an option for Template-Toolkit? I'm not very familiar with Template toolkit, so I guess it would be some kind of a plugin, and you could write [% variable | unhtml %] or some such to prevent encoding. (Actually tinita asked that on the 10. German Perl Workshop during her talk on web security and got no answer). In reply to default_escape for Template::Toolkit? by moritz
|
|