๐ฎSecurity and Escaping
HTML
p(foo=`bar"`) This <p> will be escaped.<p foo="bar"">This <p> will be escaped.</p>JavaScript
-
c := struct{
A string
B struct{C int}
}{
A: "foo",
B: struct{C int}{C: 123},
}
script.
let a = #{123};
let b = #{"abc\n"};
let c = #{c};
button(onclick="f(#{123})")
button(onclick="f(#{"abc\n"})")
button(onclick="f(#{c})")
<script>
let a = 123;
let b = "abc\n";
let c = {"A": "foo", "B": {"C": 123}};
</script>
<button onclick="f(123)"></button>
<button onclick="f("abc\n")"></button>
<button onclick="f({"A": "foo", "B": {"C": 123}})"></button>CSS
URLs
Srcset
Last updated