Packages
phoenix_html
2.4.0
4.3.0
4.2.1
4.2.0
4.1.1
4.1.0
4.0.0
3.3.4
3.3.3
3.3.2
3.3.1
3.3.0
3.2.0
3.1.0
3.0.4
3.0.3
retired
3.0.2
retired
3.0.1
retired
3.0.0
retired
2.14.3
2.14.2
2.14.1
2.14.0
2.13.4
2.13.3
2.13.2
2.13.1
2.13.0
2.12.0
2.11.2
2.11.1
2.11.0
2.10.5
2.10.4
2.10.3
2.10.2
2.10.1
2.10.0
2.9.3
2.9.2
2.9.1
2.9.0
2.8.0
2.7.0
2.7.0-dev
2.6.2
2.6.1
2.6.0
2.5.1
2.5.0
2.4.0
2.4.0-dev
2.3.1
2.3.0
2.2.0
2.1.2
2.1.1
2.1.0
2.0.1
2.0.0
2.0.0-dev
1.4.0
1.3.0
1.2.1
1.2.0
1.1.0
1.0.1
1.0.0
Phoenix view functions for working with HTML templates
Security advisory:
This version has known vulnerabilities.
View advisories
Current section
Files
Jump to
Current section
Files
lib/phoenix_html/safe.ex
defprotocol Phoenix.HTML.Safe do
@moduledoc """
Defines the HTML safe protocol.
In order to promote HTML safety, Phoenix templates
do not use `Kernel.to_string/1` to convert data types to
strings in templates. Instead, Phoenix uses this
protocol which must be implemented by data structures
and guarantee that a HTML safe representation is returned.
Furthermore, this protocol relies on iodata, which provides
better performance when sending or streaming data to the client.
"""
def to_iodata(data)
end
defimpl Phoenix.HTML.Safe, for: Atom do
def to_iodata(nil), do: ""
def to_iodata(atom), do: Plug.HTML.html_escape(Atom.to_string(atom))
end
defimpl Phoenix.HTML.Safe, for: BitString do
defdelegate to_iodata(data), to: Plug.HTML, as: :html_escape
end
defimpl Phoenix.HTML.Safe, for: List do
def to_iodata([h|t]) do
[to_iodata(h)|to_iodata(t)]
end
def to_iodata([]) do
[]
end
def to_iodata(?<), do: "<"
def to_iodata(?>), do: ">"
def to_iodata(?&), do: "&"
def to_iodata(?"), do: """
def to_iodata(?'), do: "'"
def to_iodata(h) when is_integer(h) do
h
end
def to_iodata(h) when is_binary(h) do
Plug.HTML.html_escape(h)
end
def to_iodata({:safe, data}) do
data
end
def to_iodata(other) do
raise ArgumentError,
"lists in Phoenix.HTML and templates may only contain integers, binaries or other lists, " <>
"got invalid entry: #{inspect other}"
end
end
defimpl Phoenix.HTML.Safe, for: Integer do
def to_iodata(data), do: Integer.to_string(data)
end
defimpl Phoenix.HTML.Safe, for: Float do
def to_iodata(data) do
IO.iodata_to_binary(:io_lib_format.fwrite_g(data))
end
end
defimpl Phoenix.HTML.Safe, for: Tuple do
def to_iodata({:safe, data}), do: data
def to_iodata(value) do
raise Protocol.UndefinedError,
protocol: @protocol,
value: value
end
end