amy icon indicating copy to clipboard operation
amy copied to clipboard

Review use of `mark_safe` when building HTML code in template tags

Open elichad opened this issue 1 year ago • 1 comments

          After reading https://docs.djangoproject.com/en/3.2/ref/utils/#django.utils.html.format_html I think we should review our use of `mark_safe`, as `format_html` may be more appropriate.

Originally posted by @pbanaszkiewicz in https://github.com/carpentries/amy/pull/2553#discussion_r1389697360

In the wake of https://github.com/carpentries/amy/pull/2567 I agree that this is a good idea.

elichad avatar Nov 16 '23 09:11 elichad

High priority to investigate; can be re-assessed and re-prioritised once we know if/how much work there is to do & if there are any security problems that need to be addressed urgently.

elichad avatar Nov 21 '23 15:11 elichad