summaryrefslogtreecommitdiff
path: root/docs/ref
diff options
context:
space:
mode:
authorSarah Boyce <42296566+sarahboyce@users.noreply.github.com>2025-02-21 16:47:59 +0100
committerSarah Boyce <42296566+sarahboyce@users.noreply.github.com>2025-02-24 08:51:08 +0100
commit582ba18d56167587e290545f113d3956e73a5801 (patch)
treef727f2288648faec921ba86f8fb1de163a6378ce /docs/ref
parent59353360590202fab04067e23214a825157c524b (diff)
Added security guideline on reasonable size limitations when rendering content via the DTL.
This also removes the need to add warnings for every Django template filter.
Diffstat (limited to 'docs/ref')
-rw-r--r--docs/ref/templates/builtins.txt11
1 files changed, 0 insertions, 11 deletions
diff --git a/docs/ref/templates/builtins.txt b/docs/ref/templates/builtins.txt
index b1a3236143..8851fd50ea 100644
--- a/docs/ref/templates/builtins.txt
+++ b/docs/ref/templates/builtins.txt
@@ -2920,17 +2920,6 @@ Django's built-in :tfilter:`escape` filter. The default value for
email addresses that contain single quotes (``'``), things won't work as
expected. Apply this filter only to plain text.
-.. warning::
-
- Using ``urlize`` or ``urlizetrunc`` can incur a performance penalty, which
- can become severe when applied to user controlled values such as content
- stored in a :class:`~django.db.models.TextField`. You can use
- :tfilter:`truncatechars` to add a limit to such inputs:
-
- .. code-block:: html+django
-
- {{ value|truncatechars:500|urlize }}
-
.. templatefilter:: urlizetrunc
``urlizetrunc``