32356e4eFix typo in header of shortcode-templates.mdc8f1a2d2Correct code example for index template functionbfa6a55dEscape code fencingff8b2f99Fix typos in deployment with wercker tutorial557c36e8theme: Merge commit '7fbb4bed25001182bfeb91f79db0f0c1936582ee'7fbb4bedSquashed 'themes/gohugoioTheme/' changes from 7dd8a302..ca53082dce31cee0Add "See Also" config158cee1bMake the tags into keywords61600be6Add a note to the related section49edb5a2Relase 0.27.1c9bbc001releaser: Add release notes to /docs for release of 0.27.1213c6c3bAdd bugs poster8b4590cdAdd KeyCDN integration tutorial2b277859Add tutorial videos to several docs pages950fef1fUpdate roadmap to link to the correct milestones page496f5bf6Rename relnotesd6f9378dBump Netlify versions to 0.27087fde7fUpdate 0.27 release notes603f94aedocs: Document Related Content3790f6a3releaser: Bump versions for release of 0.270948868creleaser: Add release notes to /docs for release of 0.27 git-subtree-dir: docs git-subtree-split:32356e4eab
2.6 KiB
title, description, godocref, date, publishdate, lastmod, keywords, categories, menu, signature, workson, hugoversion, relatedfuncs, deprecated, aliases
| title | description | godocref | date | publishdate | lastmod | keywords | categories | menu | signature | workson | hugoversion | relatedfuncs | deprecated | aliases | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| safeURL | Declares the provided string as a safe URL or URL substring. | https://golang.org/pkg/html/template/#HTMLEscape | 2017-02-01 | 2017-02-01 | 2017-02-01 |
|
|
|
|
false |
safeURL declares the provided string as a "safe" URL or URL substring (see RFC 3986). A URL like javascript:checkThatFormNotEditedBeforeLeavingPage() from a trusted source should go in the page, but by default dynamic javascript: URLs are filtered out since they are a frequently exploited injection vector.
Without safeURL, only the URI schemes http:, https: and mailto: are considered safe by Go templates. If any other URI schemes (e.g., irc: and javascript:) are detected, the whole URL will be replaced with #ZgotmplZ. This is to "defang" any potential attack in the URL by rendering it useless.
The following examples use a site config.toml with the following menu entry:
{{< code file="config.toml" copy="false" >}} menu.main name = "IRC: #golang at freenode" url = "irc://irc.freenode.net/#golang" {{< /code >}}
The following is an example of a sidebar partial that may be used in conjunction with the preceding front matter example:
{{< code file="layouts/partials/bad-url-sidebar-menu.html" copy="false" >}}
-
{{ range .Site.Menus.main }}
- {{ .Name }} {{ end }}
This partial would produce the following HTML output:
{{< output file="bad-url-sidebar-menu-output.html" >}}
{{< /output >}}The odd output can be remedied by adding | safeURL to our .Title page variable:
{{< code file="layouts/partials/correct-url-sidebar-menu.html" copy="false" >}}
{{< /code >}}With the .URL page variable piped through safeURL, we get the desired output:
{{< output file="correct-url-sidebar-menu-output.html" >}}
{{< /output >}}