Skip to main content

When using Jinja2-templates to output non-HTML contents, autoescaping cannot be used because it is hardcoded to work with an HTML escape function and MarkupSafe’s Markup objects.

jinja_vanish enables implementing custom auto-escapes by overriding the escape function inside the generated template code using an extended code-generator and replacing the built-in filters |e and |escape. Usage is fairly simple, here is an example that uses psycopg2’s mogrify() function to escape SQL for Postgres:

from datetime import datetime

from jinja_vanish import DynAutoEscapeEnvironment, markup_escape_func
from psycopg2.extensions import adapt

@markup_escape_func
def sql_escape(v):
    # the decorator handles wrapping/unwrapping in Markup(), but is
    # otherwise not necessary
    return adapt(v)


env = DynAutoEscapeEnvironment(autoescape=True, escape_func=sql_escape)
tpl = env.from_string('SELECT * FROM foo where post_date <= {{now}}')

print(tpl.render(now=datetime.now()))

Running it outputs:

SELECT * FROM foo where post_date <= '2016-01-24T23:23:22.727789'::timestamp

Metadata

Release files for jinja-vanish 0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for jinja-vanish 0.1
File Size Uploaded
jinja-vanish-0.1.tar.gz 2.5 kB Details

Release files / jinja-vanish-0.1.tar.gz

Download URL jinja-vanish-0.1.tar.gz
Size 2.5 kB
Tags Source
SHA-256 checksum
How to use checksums
3a28347909a9114e9b64602422e82ca70d95095bf171c447871f0aabd2a119f2
BLAKE2b-256 checksum
How to use checksums
074924f904774457a8d6a78b1061da23836066236b8ed10cf71cc0efa7823e0a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

0.2.dev1

This release

0.1 This release

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page