xss-utils
Utilities to prevent possible Cross Site Scripting (XSS) attacks on Django/Mako templates.
Overview
This repo houses utility functions to protect edx codebase (Python, Javascript and other templating engine eg django/mako) against possible XSS attacks. Helper code include html & js escaping filters for django and mako templates. For more information, please read Preventing Cross Site Scripting Vulnerabilities.
Documentation
The full documentation is in the docs directory TODO: Publish to https://xss-utils.readthedocs.org.
License
The code in this repository is licensed under the AGPL 3.0 unless otherwise noted.
Please see LICENSE.txt for details.
How To Contribute
Contributions are very welcome.
Please read How To Contribute for details.
PR description template should be automatically applied if you are sending PR from github interface; otherwise you can find it it at PULL_REQUEST_TEMPLATE.md
Issue report template should be automatically applied if you are sending it from github UI as well; otherwise you can find it at ISSUE_TEMPLATE.md
Reporting Security Issues
Please do not report security issues in public. Please email security@openedx.org.
Getting Help
Have a question about this repository, or about Open edX in general? Please refer to this list of resources if you need any assistance.
Metadata
Release files for xss-utils 1.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| xss_utils-1.1.0.tar.gz | 111.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| xss_utils-1.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 128.5 kB
Release files / xss_utils-1.1.0.tar.gz
| Download URL | xss_utils-1.1.0.tar.gz |
|---|---|
| Size | 111.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
383852db904a2c01bdc41fee795336c7cf0f7f904e233a1f0ce10fd09a81f951
|
|
BLAKE2b-256 checksum How to use checksums |
c7fdb0a09bf384e32c6367e80ff7bf4debe97d4bba349a2e0f8ee7b54982e0f6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.
Transparency logRelease files / xss_utils-1.1.0-py3-none-any.whl
| Download URL | xss_utils-1.1.0-py3-none-any.whl |
|---|---|
| Size | 16.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
e692843feacc781dd1dd507dada8337f0d58724dde308df87aee425c39bc18f8
|
|
BLAKE2b-256 checksum How to use checksums |
6109f3732065357306bc083be64f37961d48d79c68ffbafc923a5e08a13c4cb7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.
Transparency log