Skip to content

Commit aa77517

Browse files
committed
docs: clarify escaping with Parser filters
1 parent fba4362 commit aa77517

1 file changed

Lines changed: 15 additions & 6 deletions

File tree

‎user_guide_src/source/outgoing/view_parser.rst‎

Lines changed: 15 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -320,16 +320,25 @@ In this case, you will write code in your template::
320320
Escaping Data
321321
=============
322322

323-
By default, all variable substitution is escaped to help prevent XSS attacks on your pages. CodeIgniter's ``esc()`` method
324-
supports several different contexts, like general ``html``, when it's in an HTML ``attr``, in ``css``, etc. If nothing
325-
else is specified, the data will be assumed to be in an HTML context. You can specify the context used by using the ``esc()``
326-
filter::
323+
Variable substitutions without filters are escaped by default to help prevent XSS attacks on your pages.
324+
CodeIgniter's ``esc()`` method supports several contexts, such as ``html``, ``attr``, and ``css``.
325+
If no context is specified, the Parser uses ``html``. You can specify the context with the ``esc`` filter::
327326

328327
{ user_styles | esc(css) }
329328
<a href="{ user_link | esc(attr) }">{ title }</a>
330329

331-
There will be times when you absolutely need something to used and NOT escaped. You can do this by adding exclamation
332-
marks to the opening and closing braces::
330+
When a substitution uses one or more filters, the Parser does not add an ``esc`` filter automatically.
331+
This also applies when a context is specified with ``setData()`` or ``setVar()``.
332+
Add ``esc`` explicitly when filtering untrusted data. Filters run from left to right, so its position matters::
333+
334+
{ title|capitalize|esc }
335+
{ body|esc|nl2br }
336+
337+
In the second example, ``esc`` escapes the input before ``nl2br`` adds HTML ``<br>`` tags.
338+
Escaping after ``nl2br`` would display those tags as text.
339+
Unknown filter names are ignored, but still prevent automatic escaping; check filter names carefully.
340+
341+
To disable automatic escaping for a substitution without filters, add exclamation marks to its delimiters::
333342

334343
{! unescaped_var !}
335344

0 commit comments

Comments
 (0)