summaryrefslogtreecommitdiff
path: root/docs/ref
diff options
context:
space:
mode:
authorSarah Boyce <42296566+sarahboyce@users.noreply.github.com>2025-02-21 16:47:59 +0100
committerSarah Boyce <42296566+sarahboyce@users.noreply.github.com>2025-02-24 08:54:44 +0100
commitd637e251b4eff467876f46b3e87f54a7a36196e0 (patch)
treee079bbcf5761fcc6cb3c0a6003d7b015b3835bc6 /docs/ref
parent865337ae925668ac5296955f01949354a0113b01 (diff)
[5.2.x] Added security guideline on reasonable size limitations when rendering content via the DTL.
This also removes the need to add warnings for every Django template filter. Backport of 582ba18d56167587e290545f113d3956e73a5801 from main.
Diffstat (limited to 'docs/ref')
-rw-r--r--docs/ref/templates/builtins.txt11
1 files changed, 0 insertions, 11 deletions
diff --git a/docs/ref/templates/builtins.txt b/docs/ref/templates/builtins.txt
index 27644a3152..41ddca8560 100644
--- a/docs/ref/templates/builtins.txt
+++ b/docs/ref/templates/builtins.txt
@@ -2922,17 +2922,6 @@ Django's built-in :tfilter:`escape` filter. The default value for
email addresses that contain single quotes (``'``), things won't work as
expected. Apply this filter only to plain text.
-.. warning::
-
- Using ``urlize`` or ``urlizetrunc`` can incur a performance penalty, which
- can become severe when applied to user controlled values such as content
- stored in a :class:`~django.db.models.TextField`. You can use
- :tfilter:`truncatechars` to add a limit to such inputs:
-
- .. code-block:: html+django
-
- {{ value|truncatechars:500|urlize }}
-
.. templatefilter:: urlizetrunc
``urlizetrunc``