Files
hugo/content/functions/safeURL.md
T
Bud Parr 7fd64f19c8 Merge bp/theme-design branch containing Bud Parr's new design
It's a beautiful thing. A thousand thanks, Bud.

See PR rdwatters/hugo-docs-concept#118
2017-05-26 14:25:22 -05:00

2.7 KiB

title, description, godocref, date, publishdate, lastmod, tags, categories, menu, ns, signature, workson, hugoversion, relatedfuncs, deprecated, aliases
title description godocref date publishdate lastmod tags categories menu ns signature workson hugoversion relatedfuncs deprecated aliases
safeurl Declares the provided string as a safe URL or URL substring. https://golang.org/pkg/html/template/#HTMLEscape 2017-02-01 2017-02-01 2017-02-01
strings
urls
functions
docs
parent
functions
safeURL INPUT
false

safeURL declares the provided string as a "safe" URL or URL substring (see RFC 3986). A URL like javascript:checkThatFormNotEditedBeforeLeavingPage() from a trusted source should go in the page, but by default dynamic javascript: URLs are filtered out since they are a frequently exploited injection vector.

Without safeURL, only the URI schemes http:, https: and mailto: are considered safe by Go templates. If any other URI schemes (e.g., irc: and javascript:) are detected, the whole URL will be replaced with #ZgotmplZ. This is to "defang" any potential attack in the URL by rendering it useless.

The following examples use a site config.toml with the following menu entry:

{{% code file="config.toml" copy="false" %}}

[[menu.main]]
    name = "IRC: #golang at freenode"
    url = "irc://irc.freenode.net/#golang"

{{% /code %}}

The following is an example of a sidebar partial that may be used in conjunction with the preceding front matter example:

{{% code file="layouts/partials/bad-url-sidebar-menu.html" copy="false" %}}

<!-- This unordered list may be part of a sidebar menu -->
<ul>
  {{ range .Site.Menus.main }}
  <li><a href="{{ .URL }}">{{ .Name }}</a></li>
  {{ end }}
</ul>

{{% /code %}}

This partial would produce the following HTML output:

{{% output file="bad-url-sidebar-menu-output.html" %}}

<!-- This unordered list may be part of a sidebar menu -->
<ul>
    <li><a href="#ZgotmplZ">IRC: #golang at freenode</a></li>
</ul>

{{% /output %}}

The odd output can be remedied by adding | safeURL to our .Title page variable:

{{% code file="layouts/partials/correct-url-sidebar-menu.html" copy="false" %}}

<!-- This unordered list may be part of a sidebar menu -->
<ul>
    <li><a href="{{ .URL | safeURL }}">{{ .Name }}</a></li>
</ul>

{{% /code %}}

With the .URL page variable piped through safeURL, we get the desired output:

{{% output file="correct-url-sidebar-menu-output.html" %}}

<ul class="sidebar-menu">
    <li><a href="irc://irc.freenode.net/#golang">IRC: #golang at freenode</a></li>
</ul>

{{% /output %}}