mirror of
https://github.com/twigphp/Twig.git
synced 2026-09-15 20:06:31 +00:00
Added disambiguation on using raw in expressions
This commit is contained in:
@@ -10,3 +10,27 @@ if ``raw`` is the last filter applied to it:
|
|||||||
{% autoescape %}
|
{% autoescape %}
|
||||||
{{ var|raw }} {# var won't be escaped #}
|
{{ var|raw }} {# var won't be escaped #}
|
||||||
{% endautoescape %}
|
{% endautoescape %}
|
||||||
|
|
||||||
|
.. note::
|
||||||
|
|
||||||
|
Be careful when using the ``raw`` filter inside expressions. This
|
||||||
|
snippet illustrates a case that can be confusing :
|
||||||
|
|
||||||
|
.. code-block:: jinja
|
||||||
|
|
||||||
|
{% autoescape %}
|
||||||
|
{% set hello = '<strong>Hello</strong>' %}
|
||||||
|
{% set hola = '<strong>Hola</strong>' %}
|
||||||
|
|
||||||
|
{{ false ? '<strong>Hola</strong>' : hello|raw }}
|
||||||
|
does not render the same as
|
||||||
|
{{ false ? hola : hello|raw }}
|
||||||
|
but renders the same as
|
||||||
|
{{ (false ? hola : hello)|raw }}
|
||||||
|
{% endautoescape %}
|
||||||
|
|
||||||
|
The first ternary won't be escaped : ``hello`` is marked as being safe and
|
||||||
|
Twig does not escape static values (see :doc:`escape<../tags/autoescape>`).
|
||||||
|
In the second ternary, even if ``hello`` is marked as safe, ``hola``
|
||||||
|
remains unsafe and so will be the whole expression. On the other hand, the
|
||||||
|
third ternary will be marked as safe and the result won't be escaped.
|
||||||
+14
-1
@@ -65,7 +65,20 @@ Functions returning template data (like :doc:`macros<macro>` and
|
|||||||
Twig is smart enough to not escape an already escaped value by the
|
Twig is smart enough to not escape an already escaped value by the
|
||||||
:doc:`escape<../filters/escape>` filter.
|
:doc:`escape<../filters/escape>` filter.
|
||||||
|
|
||||||
|
.. note::
|
||||||
|
|
||||||
|
Twig does not escape static expressions :
|
||||||
|
|
||||||
|
.. code-block:: jinja
|
||||||
|
|
||||||
|
{% set hello = "<strong>Hello</strong>" %}
|
||||||
|
{{ hello }}
|
||||||
|
{{ "<strong>world</strong>" }}
|
||||||
|
|
||||||
|
Will be rendered "<strong>Hello</strong> **world**".
|
||||||
|
|
||||||
|
|
||||||
.. note::
|
.. note::
|
||||||
|
|
||||||
The chapter :doc:`Twig for Developers<../api>` gives more information
|
The chapter :doc:`Twig for Developers<../api>` gives more information
|
||||||
about when and how automatic escaping is applied.
|
about when and how automatic escaping is applied.
|
||||||
Reference in New Issue
Block a user