forked from orbit-oss/flask
deprecate markupsafe exports
This commit is contained in:
parent
1ee22e1736
commit
9c02f07f9b
8 changed files with 41 additions and 20 deletions
|
|
@ -23,7 +23,7 @@ in templates, but there are still other places where you have to be
|
|||
careful:
|
||||
|
||||
- generating HTML without the help of Jinja2
|
||||
- calling :class:`~flask.Markup` on data submitted by users
|
||||
- calling :class:`~markupsafe.Markup` on data submitted by users
|
||||
- sending out HTML from uploaded files, never do that, use the
|
||||
``Content-Disposition: attachment`` header to prevent that problem.
|
||||
- sending out textfiles from uploaded files. Some browsers are using
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue