4 ms·
Tiny templating libraries like mustache are ideal for that. https://mustache.github.io/ https://mustache.github.io/
by ktzar 6y ago
Tiny templating libraries like mustache are ideal for that. https://mustache.github.io/ https://mustache.github.io/
- hombre_fatal 6y agoCould never get over Mustache using {{foo}} for safe auto-escaped interpolation but {{{foo}}} for dangerous non-escaped interpolation. I wonder how many XSS vulns this decision has caused in the wild.
- onei 6y agoI'd say that's the more sensible decision if you want to maintain syntax. You can grep for {{{ without false positives matching {{. Conversely, it's harder to find places where == was used when === should have been used (although I'll concede it's not much harder). In general I'd prefer to go the extra mile to be unsafe than accidentally miss something out.
- hombre_fatal 6y agoMaybe my point wasn't clear, but {{{ and {{ look too similar. It should be {{ and something else. Like {{Dangerous=username}}. You shouldn't have to squint at your templating code to see if there's an XSS vector or not, or defensively/neurotically grep for "{{{" just in case you didn't trust your team to squint sufficiently. For comparison, here's JSX: <div dangerouslySetInnerHTML={{__html: username}} />. vs. Mustache: {{{username}}} in a file of 1000 other { and } glyphs. Mustache's hey-dey is long over thankfully.
- onei 6y agoI agree that something possibly dangerous should be harder to mis-use. The world is full of small oversights. Having said that, surely this is the job of a linter - does one exist for mustache? I've never seen JSX before (I haven't learned anything new in front-end later than ES5). In your example, it looks more like an attribute than an inner tag, the former of which I'd almost always escape. Is that how you set inner HTML as well?