@@ -320,16 +320,25 @@ In this case, you will write code in your template::
320320Escaping Data
321321=============
322322
323- By default, all variable substitution is escaped to help prevent XSS attacks on your pages. CodeIgniter's ``esc() `` method
324- supports several different contexts, like general ``html ``, when it's in an HTML ``attr ``, in ``css ``, etc. If nothing
325- else is specified, the data will be assumed to be in an HTML context. You can specify the context used by using the ``esc() ``
326- filter::
323+ Variable substitutions without filters are escaped by default to help prevent XSS attacks on your pages.
324+ CodeIgniter's ``esc() `` method supports several contexts, such as ``html ``, ``attr ``, and ``css ``.
325+ If no context is specified, the Parser uses ``html ``. You can specify the context with the ``esc `` filter::
327326
328327 { user_styles | esc(css) }
329328 <a href="{ user_link | esc(attr) }">{ title }</a>
330329
331- There will be times when you absolutely need something to used and NOT escaped. You can do this by adding exclamation
332- marks to the opening and closing braces::
330+ When a substitution uses one or more filters, the Parser does not add an ``esc `` filter automatically.
331+ This also applies when a context is specified with ``setData() `` or ``setVar() ``.
332+ Add ``esc `` explicitly when filtering untrusted data. Filters run from left to right, so its position matters::
333+
334+ { title|capitalize|esc }
335+ { body|esc|nl2br }
336+
337+ In the second example, ``esc `` escapes the input before ``nl2br `` adds HTML ``<br> `` tags.
338+ Escaping after ``nl2br `` would display those tags as text.
339+ Unknown filter names are ignored, but still prevent automatic escaping; check filter names carefully.
340+
341+ To disable automatic escaping for a substitution without filters, add exclamation marks to its delimiters::
333342
334343 {! unescaped_var !}
335344
0 commit comments