Re: [Django] #34595: format_html() should explicitly mention that format_string is not escaped and that result is safe

9 views
Skip to first unread message

Django

unread,
May 26, 2023, 6:10:44 AM5/26/23
to django-...@googlegroups.com
#34595: format_html() should explicitly mention that format_string is not escaped
and that result is safe
--------------------------------------+------------------------------------
Reporter: Natalia Bidart | Owner: AP Jama
Type: Cleanup/optimization | Status: assigned
Component: Template system | Version: 4.2
Severity: Normal | Resolution:
Keywords: | Triage Stage: Accepted
Has patch: 0 | Needs documentation: 0
Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 1 | UI/UX: 0
--------------------------------------+------------------------------------
Changes (by AP Jama):

* owner: nobody => AP Jama
* status: new => assigned


--
Ticket URL: <https://code.djangoproject.com/ticket/34595#comment:4>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

Django

unread,
Jun 1, 2023, 6:51:23 AM6/1/23
to django-...@googlegroups.com
#34595: format_html() should explicitly mention that format_string is not escaped
and that result is safe
--------------------------------------+------------------------------------
Reporter: Natalia Bidart | Owner: AP Jama
Type: Cleanup/optimization | Status: assigned
Component: Template system | Version: 4.2
Severity: Normal | Resolution:
Keywords: | Triage Stage: Accepted
Has patch: 1 | Needs documentation: 0

Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 1 | UI/UX: 0
--------------------------------------+------------------------------------
Changes (by Mariusz Felisiak):

* has_patch: 0 => 1


Comment:

[https://code.djangoproject.com/ticket/34595 PR]

--
Ticket URL: <https://code.djangoproject.com/ticket/34595#comment:5>

Django

unread,
Jun 1, 2023, 7:12:28 AM6/1/23
to django-...@googlegroups.com
#34595: format_html() should explicitly mention that format_string is not escaped
and that result is safe
-------------------------------------+-------------------------------------

Reporter: Natalia Bidart | Owner: AP Jama
Type: | Status: assigned
Cleanup/optimization |

Component: Template system | Version: 4.2
Severity: Normal | Resolution:
Keywords: | Triage Stage: Ready for
| checkin

Has patch: 1 | Needs documentation: 0
Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 1 | UI/UX: 0
-------------------------------------+-------------------------------------
Changes (by Mariusz Felisiak):

* stage: Accepted => Ready for checkin


--
Ticket URL: <https://code.djangoproject.com/ticket/34595#comment:6>

Django

unread,
Jun 1, 2023, 8:10:38 AM6/1/23
to django-...@googlegroups.com
#34595: format_html() should explicitly mention that format_string is not escaped
and that result is safe
-------------------------------------+-------------------------------------
Reporter: Natalia Bidart | Owner: AP Jama
Type: | Status: closed

Cleanup/optimization |
Component: Template system | Version: 4.2
Severity: Normal | Resolution: fixed

Keywords: | Triage Stage: Ready for
| checkin
Has patch: 1 | Needs documentation: 0
Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 1 | UI/UX: 0
-------------------------------------+-------------------------------------
Changes (by Mariusz Felisiak <felisiak.mariusz@…>):

* status: assigned => closed
* resolution: => fixed


Comment:

In [changeset:"4037223d0f12c44ecd6f369ccbabcbd279a1bdbc" 4037223d]:
{{{
#!CommitTicketReference repository=""
revision="4037223d0f12c44ecd6f369ccbabcbd279a1bdbc"
Fixed #34595 -- Doc'd that format_string arg of format_html() is not
escaped.
}}}

--
Ticket URL: <https://code.djangoproject.com/ticket/34595#comment:7>

Django

unread,
Jun 1, 2023, 8:17:16 AM6/1/23
to django-...@googlegroups.com
#34595: format_html() should explicitly mention that format_string is not escaped
and that result is safe
-------------------------------------+-------------------------------------
Reporter: Natalia Bidart | Owner: AP Jama
Type: | Status: closed
Cleanup/optimization |
Component: Template system | Version: 4.2
Severity: Normal | Resolution: fixed
Keywords: | Triage Stage: Ready for
| checkin
Has patch: 1 | Needs documentation: 0
Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 1 | UI/UX: 0
-------------------------------------+-------------------------------------

Comment (by Mariusz Felisiak <felisiak.mariusz@…>):

In [changeset:"dae052d823dd66edcd0dd7fe5542d2c6a3a498d0" dae052d]:
{{{
#!CommitTicketReference repository=""
revision="dae052d823dd66edcd0dd7fe5542d2c6a3a498d0"
[4.2.x] Fixed #34595 -- Doc'd that format_string arg of format_html() is
not escaped.

Backport of 4037223d0f12c44ecd6f369ccbabcbd279a1bdbc from main
}}}

--
Ticket URL: <https://code.djangoproject.com/ticket/34595#comment:8>

Reply all
Reply to author
Forward
0 new messages