Flask Academy · 课时

自动转义与 safe 过滤器

确保 XSS 安全,仅在确定安全时退出转义

第 4 / 4 课13 个步骤

自动转义与 safe 过滤器 是 CoddyKit 上的免费 Flask Academy 课时。 这是第 4 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Flask Academy 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Flask Academy 课程共包含 4 节课。

本课时的部分内容尚未翻译,以英文显示。

The Danger of Raw HTML

If you print user text straight into a page, a sneaky input could inject scripts. This attack is called XSS, and Flask defends against it.

Autoescaping Is On

By default Jinja2 turns on autoescaping for HTML templates. Dangerous characters get neutralized before they reach the browser.

What Escaping Does

Escaping converts characters like the less-than sign into safe entities. The browser then shows them as text, never as live markup.

<b>hi</b>  becomes  &lt;b&gt;hi&lt;/b&gt;

Why Text Stays Text

Because tags are escaped, a comment like a fake bold tag shows up as plain text. The page renders it literally instead of running it.

When You Trust the HTML

Sometimes you truly want HTML rendered, like a value you built yourself. For that you can opt out with the safe filter.

{{ trusted_html|safe }}

How safe Works

The safe filter tells Jinja2 this value is already trusted, so do not escape it. The markup then renders as real HTML.

Only on Trusted Data

Use safe only on content you control. Marking user input safe reopens the very XSS hole autoescaping was closing.

Marking Safe in Python

You can also flag trusted HTML in your view with Markup. A Markup string skips escaping automatically when rendered.

from markupsafe import Markup
snippet = Markup('<b>Hi</b>')

Disabling Escaping Locally

To skip escaping for a whole region, wrap it in an autoescape block set to false. Use this rarely and with great care.

{% autoescape false %}{{ html }}{% endautoescape %}

The escape Filter

You can also force escaping with the escape filter, or its short alias e. It is handy when autoescaping is off for a block.

{{ value|e }}

Safe by Default

The big idea: Flask is secure out of the box. You only relax escaping deliberately, never by accident, which keeps users protected.

Quick Check

You print untrusted user input in a template. What does autoescaping do with HTML tags in it?

Recap

You learned Flask autoescapes output to block XSS, and that the safe filter opts out only for HTML you fully trust. Stay secure! 🔒

免费开始

用 AI 导师学习 Python — 免费

在浏览器中编写并运行真实代码,获得全天候 AI 导师的即时帮助,并在网页或应用中继续学习。

课程
30
课程
120

常见问题解答

「自动转义与 safe 过滤器」课时是免费的吗?

是的 — 「自动转义与 safe 过滤器」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Flask Academy 课程的其余内容,请升级到 CoddyKit PRO。 Flask Academy 课程共包含 4 节课。

「自动转义与 safe 过滤器」这节课中我会学到什么?

确保 XSS 安全,仅在确定安全时退出转义 你通过在浏览器中直接运行的动手代码来练习 Flask Academy,全天候 AI 导师会在你学习这节课的过程中回答你的问题。

学习 Flask Academy 需要有经验吗?

无需任何先前经验。CoddyKit 上的 Flask Academy 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 4 节课,共 4 节。

「自动转义与 safe 过滤器」课时需要多长时间?

大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。

我能在这节 Flask Academy 课中编写并运行代码吗?

能。每节 Flask Academy 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。

此课程中的所有课时

  1. render_template 与 templates 文件夹
  2. 将数据传入模板
  3. Jinja2 循环与条件语句
  4. 自动转义与 safe 过滤器
← 返回 Flask Academy