Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 19 additions & 0 deletions latte/cs/extending-latte.texy
Original file line number Diff line number Diff line change
Expand Up @@ -219,6 +219,25 @@ public function getProviders(): array
```


getAttributeContexts(): array .[method]{data-version:3.2.0}
-----------------------------------------------------------

Vol谩 se p艡ed kompilac铆 a vykreslen铆m 拧ablony. Latte escapuje hodnotu ka啪d茅ho atributu podle toho, co s n铆 ud臎l谩 prohl铆啪e膷: atributy `on*` jako `onclick` obsahuj铆 JavaScript, `style` obsahuje CSS a `srcdoc` cel媒 HTML dokument. JavaScriptov茅 knihovny p艡id谩vaj铆 vlastn铆 atributy tohoto druhu, o nich ale Latte nem暖啪e v臎d臎t, a tak je escapuje jako kter媒koliv jin媒 atribut. To nesta膷铆: prohl铆啪e膷 hodnotu atributu dek贸duje a knihovna v媒sledek spust铆 jako k贸d nebo ho vlo啪铆 do str谩nky jako HTML. Tato metoda Latte 艡ekne, co takov茅 atributy obsahuj铆. Vrac铆 pole, jeho啪 kl铆膷i jsou n谩zvy atribut暖 a hodnotami `Latte\ContentType::JavaScript`, `Latte\ContentType::Css` nebo `Latte\ContentType::Html`. N谩zev kon膷铆c铆 `*` pokryje v拧echny atributy za膷铆naj铆c铆 dan媒m prefixem:

```php
public function getAttributeContexts(): array
{
return [
'x-on:*' => Latte\ContentType::JavaScript, // obsluha ud谩lost铆 v Alpine.js
'@*' => Latte\ContentType::JavaScript, // zkratka @click z Alpine.js
'data-tippy-content' => Latte\ContentType::Html, // tooltip Tippy.js s volbou allowHTML
];
}
```

Latte pak tyto atributy escapuje p艡esn臎 jako jejich vestav臎n茅 prot臎j拧ky: `x-on:click` jako `onclick` a `data-tippy-content` jako `srcdoc` (viz [HTML dokument v atributu srcdoc |html-attributes#HTML dokument v atributu srcdoc]). Plat铆 to pro v拧echny zp暖soby z谩pisu atributu v膷etn臎 `n:attr`. Na velikosti p铆smen v n谩zvech nez谩le啪铆, a pokud stejn媒 n谩zev zaregistruje v铆ce roz拧铆艡en铆, plat铆 to posledn铆. Vestav臎n茅 atributy `on*`, `style` a `srcdoc` p艡edefinovat nelze. Kontexty nemus铆te zahrnovat do `getCacheKey()`, Latte s nimi po膷铆t谩 samo.


getCacheKey(Latte\Engine $engine): mixed .[method]
--------------------------------------------------

Expand Down
28 changes: 28 additions & 0 deletions latte/cs/html-attributes.texy
Original file line number Diff line number Diff line change
Expand Up @@ -133,6 +133,34 @@ Stejn臎 jako `class` p艡ij铆maj铆 i atributy `aria-` pole. To se zpracuje jako s
```


HTML dokument v atributu srcdoc .{data-version:3.2.0}
=====================================================

Atribut `srcdoc` elementu `<iframe>` obsahuje cel媒 HTML dokument. Latte proto hodnotu escapuje dvakr谩t: nejprve jako HTML text a pot茅 jako atribut. 艠et臎zec se v r谩mu zobraz铆 jako prost媒 text a nem暖啪e do n臎j vlo啪it 啪谩dn茅 zna膷ky:

```latte
<iframe srcdoc={$text}></iframe>
```

Pokud `$text` obsahuje `<b>Ahoj</b>`, vykresl铆 se:

```latte
<iframe srcdoc="&amp;lt;b&amp;gt;Ahoj&amp;lt;/b&amp;gt;"></iframe>
```

Chcete-li vlo啪it d暖v臎ryhodn茅 HTML, p艡edejte ho jako objekt `Latte\Runtime\Html`. Jeho zna膷ky z暖stanou zachov谩ny a escapuje se jen jednou, jako atribut, tak啪e stejn媒 obsah se vykresl铆 jako `srcdoc="&lt;b&gt;Ahoj&lt;/b&gt;"`.

P艡edchoz铆 verze vkl谩daly 艡et臎zce jako HTML. Takov茅 hodnoty odhal铆 [migra膷n铆 varov谩n铆 |develop#Migra膷n铆 varov谩n铆], pokud je hodnotou atributu jedin媒 v媒raz `{...}`.


Atributy JavaScriptov媒ch knihoven .{data-version:3.2.0}
=======================================================

Latte v铆, 啪e atributy `on*` jako `onclick` obsahuj铆 JavaScript, `style` obsahuje CSS a `srcdoc` HTML dokument, a podle toho escapuje hodnoty v nich. Knihovny jako Alpine.js nebo Tippy.js p艡in谩拧ej铆 vlastn铆 atributy tohoto druhu, nap艡. `x-on:click` s JavaScriptov媒m k贸dem nebo `data-tippy-content` s HTML. Ve v媒choz铆m stavu je Latte escapuje jako kter媒koliv jin媒 atribut. To nesta膷铆: prohl铆啪e膷 hodnotu atributu dek贸duje a knihovna v媒sledek spust铆 jako k贸d nebo ho vlo啪铆 do str谩nky jako HTML.

Co tyto atributy obsahuj铆, m暖啪ete Latte sd臎lit v [roz拧铆艡en铆 |extending-latte#getAttributeContexts]. Pak se `x-on:click="select({$item})"` escapuje p艡esn臎 jako `onclick="select({$item})"` a `data-tippy-content={$help}` p艡esn臎 jako `srcdoc={$help}`.


Typov谩 kontrola
===============

Expand Down
19 changes: 19 additions & 0 deletions latte/en/extending-latte.texy
Original file line number Diff line number Diff line change
Expand Up @@ -219,6 +219,25 @@ public function getProviders(): array
```


getAttributeContexts(): array .[method]{data-version:3.2.0}
-----------------------------------------------------------

It is called before the template is compiled and rendered. Latte escapes each attribute value according to what the browser does with it: `on*` attributes such as `onclick` contain JavaScript, `style` contains CSS and `srcdoc` a whole HTML document. JavaScript libraries add their own attributes of this kind, but Latte cannot know about them and escapes them like any other attribute. That is not enough: the browser decodes the attribute, and the library then runs the result as code or inserts it into the page as HTML. This method tells Latte what such attributes contain. It returns an array whose keys are attribute names and whose values are `Latte\ContentType::JavaScript`, `Latte\ContentType::Css` or `Latte\ContentType::Html`. A name ending with `*` covers all attributes starting with that prefix:

```php
public function getAttributeContexts(): array
{
return [
'x-on:*' => Latte\ContentType::JavaScript, // Alpine.js event handlers
'@*' => Latte\ContentType::JavaScript, // Alpine.js shorthand @click
'data-tippy-content' => Latte\ContentType::Html, // Tippy.js tooltip with allowHTML
];
}
```

Latte then escapes these attributes exactly like their built-in counterparts: `x-on:click` like `onclick` and `data-tippy-content` like `srcdoc` (see [HTML documents in srcdoc |html-attributes#HTML Documents in srcdoc]). This applies to every way of writing an attribute, including `n:attr`. Names are case-insensitive, and if several extensions register the same name, the last one wins. The built-in attributes `on*`, `style` and `srcdoc` cannot be redefined. You don't have to include the contexts in `getCacheKey()` because Latte takes them into account itself.


getCacheKey(Latte\Engine $engine): mixed .[method]
--------------------------------------------------

Expand Down
28 changes: 28 additions & 0 deletions latte/en/html-attributes.texy
Original file line number Diff line number Diff line change
Expand Up @@ -133,6 +133,34 @@ Just like `class`, `aria-` attributes also accept an array. It is treated as a s
```


HTML Documents in srcdoc .{data-version:3.2.0}
==============================================

The `srcdoc` attribute of `<iframe>` contains a whole HTML document. Latte therefore escapes a value twice: first as HTML text and then as an attribute. A string is displayed in the frame as plain text and cannot inject any markup:

```latte
<iframe srcdoc={$text}></iframe>
```

If `$text` is `<b>Hi</b>`, it renders:

```latte
<iframe srcdoc="&amp;lt;b&amp;gt;Hi&amp;lt;/b&amp;gt;"></iframe>
```

To insert trusted HTML, pass it as a `Latte\Runtime\Html` object. Its markup is kept and escaped only once, as an attribute, so the same content renders as `srcdoc="&lt;b&gt;Hi&lt;/b&gt;"`.

Previous versions inserted strings as HTML. The [migration warnings |develop#Migration Warnings] point out such values when the entire attribute value is a single `{...}` expression.


Attributes of JavaScript Libraries .{data-version:3.2.0}
========================================================

Latte knows that `on*` attributes such as `onclick` contain JavaScript, `style` contains CSS and `srcdoc` an HTML document, and escapes values in them accordingly. Libraries such as Alpine.js or Tippy.js bring their own attributes of this kind, e.g. `x-on:click` with JavaScript code or `data-tippy-content` with HTML. By default, Latte escapes them like any other attribute. That is not enough: the browser decodes the attribute, and the library then runs the result as code or inserts it into the page as HTML.

You can tell Latte what these attributes contain in an [extension |extending-latte#getAttributeContexts]. Then `x-on:click="select({$item})"` is escaped exactly like `onclick="select({$item})"`, and `data-tippy-content={$help}` exactly like `srcdoc={$help}`.


Type Checking
=============

Expand Down
Loading