1
0
mirror of https://github.com/django/django.git synced 2025-04-16 13:24:38 +00:00
David D Lowe bfc83d8ff9 Documented risk of XSS vulnerability when using Postgres headlines.
Because the default start and stop parameters are <b> and </b>
respectively, it is tempting to pass the headline value to the `safe`
template filter, to render the highlighted section of the headline in
bold. This is dangerous.

Also, tested the sanitation behavior of Postgres. If the undocumented
behavior of Postgres changes in this regard, we want to ensure that
Django's code and documentation is updated appropriately.
2024-08-27 15:08:54 +01:00
..

The documentation in this tree is in plain text files and can be viewed using
any text file viewer.

It uses `ReST`_ (reStructuredText), and the `Sphinx`_ documentation system.
This allows it to be built into other forms for easier viewing and browsing.

To create an HTML version of the docs:

* Install Sphinx (using ``python -m pip install Sphinx`` or some other method).

* In this docs/ directory, type ``make html`` (or ``make.bat html`` on
  Windows) at a shell prompt.

The documentation in ``_build/html/index.html`` can then be viewed in a web
browser.

.. _ReST: https://docutils.sourceforge.io/rst.html
.. _Sphinx: https://www.sphinx-doc.org/