Using html/template.HTML like we were doing before caused nested include to be HTML-escaped, which breaks sites. Now we do not escape any of the output; template input is usually trusted, and if it's not, users should employ escaping actions within their templates to keep it safe. The docs already said this. |
||
|---|---|---|
| .. | ||
| caddyfile.go | ||
| frontmatter.go | ||
| templates.go | ||
| tplcontext.go | ||
| tplcontext_test.go | ||