diff options
Diffstat (limited to 'docs/ref/templates')
| -rw-r--r-- | docs/ref/templates/builtins.txt | 38 |
1 files changed, 0 insertions, 38 deletions
diff --git a/docs/ref/templates/builtins.txt b/docs/ref/templates/builtins.txt index 9bf22e4740..1623ff357b 100644 --- a/docs/ref/templates/builtins.txt +++ b/docs/ref/templates/builtins.txt @@ -1866,44 +1866,6 @@ For example:: If ``value`` is the list ``['a', 'b', 'c', 'd']``, the output could be ``"b"``. -.. templatefilter:: removetags - -removetags -^^^^^^^^^^ - -.. deprecated:: 1.8 - - ``removetags`` cannot guarantee HTML safe output and has been deprecated due - to security concerns. Consider using `bleach`_ instead. - -.. _bleach: http://bleach.readthedocs.org/en/latest/ - -Removes a space-separated list of [X]HTML tags from the output. - -For example:: - - {{ value|removetags:"b span" }} - -If ``value`` is ``"<b>Joel</b> <button>is</button> a <span>slug</span>"`` the -unescaped output will be ``"Joel <button>is</button> a slug"``. - -Note that this filter is case-sensitive. - -If ``value`` is ``"<B>Joel</B> <button>is</button> a <span>slug</span>"`` the -unescaped output will be ``"<B>Joel</B> <button>is</button> a slug"``. - -.. admonition:: No safety guarantee - - Note that ``removetags`` doesn't give any guarantee about its output being - HTML safe. In particular, it doesn't work recursively, so an input like - ``"<sc<script>ript>alert('XSS')</sc</script>ript>"`` won't be safe even if - you apply ``|removetags:"script"``. So if the input is user provided, - **NEVER** apply the ``safe`` filter to a ``removetags`` output. If you are - looking for something more robust, you can use the ``bleach`` Python - library, notably its `clean`_ method. - -.. _clean: http://bleach.readthedocs.org/en/latest/clean.html - .. templatefilter:: rjust rjust |
