mirror of
https://github.com/gohugoio/hugo.git
synced 2026-09-03 12:12:37 +00:00
2c0d1ccdcd
73f355ceUpdate theme83ff50c2Use example.com in examples71292134Add alias news > release-notes2e15f642Update theme8eef09d2Add Pygments configuration572b9e75Clean up the code shortcode usea1b2fd3bRemove the code fence language codes1473b1d9Remove redundant textb92c2042Update theme8f439c28Edit contributing section in README8bcf8a19Add contributing section to README4c44ee1cFix broken content file2bdc7710Clarify .Data.Pages sorting in lists.md092271c2Use infinitive mood for main titlesb9b8abefUpdate theme to reflect change to home page contentb897b71bChange copy to use sentence casefd675ee5Enable RSS feed for sections060a5e27Correct movie title in taxonomies.md6a5ca96aUpdate displayed site name for Hub22f4b7a4Add example of starting up the local serverd9612cb3Update themea8c3988aUpdate theme4198189dUpdate theme12d6b016Update theme2b1c4197Update themeb6d90a1eFix News release titlescfe751dbAdd some build info to README git-subtree-dir: docs git-subtree-split:73f355ce0d
77 lines
2.6 KiB
Markdown
77 lines
2.6 KiB
Markdown
---
|
|
title: safeURL
|
|
description: Declares the provided string as a safe URL or URL substring.
|
|
godocref: https://golang.org/pkg/html/template/#HTMLEscape
|
|
date: 2017-02-01
|
|
publishdate: 2017-02-01
|
|
lastmod: 2017-02-01
|
|
#tags: [strings,urls]
|
|
categories: [functions]
|
|
menu:
|
|
docs:
|
|
parent: "functions"
|
|
signature: ["safeURL INPUT"]
|
|
workson: []
|
|
hugoversion:
|
|
relatedfuncs: []
|
|
deprecated: false
|
|
aliases: []
|
|
---
|
|
|
|
`safeURL` declares the provided string as a "safe" URL or URL substring (see [RFC 3986][]). A URL like `javascript:checkThatFormNotEditedBeforeLeavingPage()` from a trusted source should go in the page, but by default dynamic `javascript:` URLs are filtered out since they are a frequently exploited injection vector.
|
|
|
|
Without `safeURL`, only the URI schemes `http:`, `https:` and `mailto:` are considered safe by Go templates. If any other URI schemes (e.g., `irc:` and `javascript:`) are detected, the whole URL will be replaced with `#ZgotmplZ`. This is to "defang" any potential attack in the URL by rendering it useless.
|
|
|
|
The following examples use a [site `config.toml`][configuration] with the following [menu entry][menus]:
|
|
|
|
{{< code file="config.toml" copy="false" >}}
|
|
[[menu.main]]
|
|
name = "IRC: #golang at freenode"
|
|
url = "irc://irc.freenode.net/#golang"
|
|
{{< /code >}}
|
|
|
|
The following is an example of a sidebar partial that may be used in conjunction with the preceding front matter example:
|
|
|
|
{{< code file="layouts/partials/bad-url-sidebar-menu.html" copy="false" >}}
|
|
<!-- This unordered list may be part of a sidebar menu -->
|
|
<ul>
|
|
{{ range .Site.Menus.main }}
|
|
<li><a href="{{ .URL }}">{{ .Name }}</a></li>
|
|
{{ end }}
|
|
</ul>
|
|
{{< /code >}}
|
|
|
|
This partial would produce the following HTML output:
|
|
|
|
{{% output file="bad-url-sidebar-menu-output.html" %}}
|
|
```
|
|
<!-- This unordered list may be part of a sidebar menu -->
|
|
<ul>
|
|
<li><a href="#ZgotmplZ">IRC: #golang at freenode</a></li>
|
|
</ul>
|
|
```
|
|
{{% /output %}}
|
|
|
|
The odd output can be remedied by adding ` | safeURL` to our `.Title` page variable:
|
|
|
|
{{< code file="layouts/partials/correct-url-sidebar-menu.html" copy="false" >}}
|
|
<!-- This unordered list may be part of a sidebar menu -->
|
|
<ul>
|
|
<li><a href="{{ .URL | safeURL }}">{{ .Name }}</a></li>
|
|
</ul>
|
|
{{< /code >}}
|
|
|
|
With the `.URL` page variable piped through `safeURL`, we get the desired output:
|
|
|
|
{{% output file="correct-url-sidebar-menu-output.html" %}}
|
|
```
|
|
<ul class="sidebar-menu">
|
|
<li><a href="irc://irc.freenode.net/#golang">IRC: #golang at freenode</a></li>
|
|
</ul>
|
|
```
|
|
{{% /output %}}
|
|
|
|
[configuration]: /getting-started/configuration/
|
|
[menus]: /content-management/menus/
|
|
[RFC 3986]: http://tools.ietf.org/html/rfc3986
|