Python: Require quote escaping for html.escape

This commit is contained in:
Rasmus Wriedt Larsen
2024-01-30 12:17:01 +01:00
parent 00dc55d825
commit c70b32f7eb
2 changed files with 16 additions and 3 deletions

View File

@@ -4,5 +4,6 @@ s = "tainted"
html.escape(s) # $ escapeInput=s escapeKind=html escapeOutput=html.escape(..)
html.escape(s, True) # $ escapeInput=s escapeKind=html escapeOutput=html.escape(..)
html.escape(s, False) # $ escapeInput=s escapeKind=html escapeOutput=html.escape(..)
html.escape(s, quote=False) # $ escapeInput=s escapeKind=html escapeOutput=html.escape(..)
# not considered html escapes, since they don't escape all relevant characters
html.escape(s, False)
html.escape(s, quote=False)