|
UnENVerse 0.42.6
Local-first desktop secrets manager — TypeScript frontend
|
Escape by construction (Phase 28, review-01 §2.3, ADR-0136). More...
Public Member Functions | |
| constructor (private readonly markup:string) | |
Escape by construction (Phase 28, review-01 §2.3, ADR-0136).
html is a tagged template that escapes every interpolated value unless it is already a SafeHtml, which only html itself and raw() can produce. A renderer therefore cannot forget to escape: forgetting is the default that is safe, and the opt-out is a visible, greppable raw(...).
html<b title="${entry.provider}">${entry.notes}</b> // both escaped html<ul>${items.map((i) => html${i})}</ul> // nested + arrays
Escaping is the attribute-strength set (‘& < > " ’), so one rule is correct in text and in a quoted attribute. It does NOT makehref/srcsafe: ajavascript:URL survives HTML escaping, so links still go through safeHttpUrl`. Markup that has been escaped or vouched for. Only html/raw build one.
| SafeHtml::constructor | ( | private readonly markup:string | ) |