AlexP has asked for the wisdom of the Perl Monks concerning the following question:
Hi monks! Today I started studying Dancer with this tutorial and maybe I'm getting ahead but I wonder is there a way to apply default html filter to all variables?
So far I've only seen an example with explicit syntax like:
[% entries.$id.text | html %]However, it seems to me that this approach may lead to the fact that developer may forget to apply the filter and xss will occurs.
Searching for this topic led me to node and to Template::AutoFilter but it was in early 2011.
Should i use this approach today or there are modern ways to achieve this?
And can I use this with dancer?
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Dancer + template toolkit default html filter
by Your Mother (Archbishop) on Jul 25, 2021 at 22:27 UTC | |
by AlexP (Pilgrim) on Jul 26, 2021 at 16:00 UTC | |
|
Re: Dancer + template toolkit default html filter
by AlexP (Pilgrim) on Jul 28, 2021 at 14:28 UTC | |
|
Re: Dancer + template toolkit default html filter
by AlexP (Pilgrim) on Aug 15, 2021 at 17:09 UTC | |
by AlexP (Pilgrim) on Aug 15, 2021 at 18:43 UTC | |
by AlexP (Pilgrim) on Aug 15, 2021 at 17:10 UTC |