Django में XSS Protection
{{ variable }} <!-- escaped automatically: safe -->
{{ variable|safe }} <!-- rendered as raw HTML: only for trusted content -->
Templates में Auto-Escaping
Default रूप से, Django template में {{ variable }} से render होने वाली हर variable HTML-escaped होती है। अगर एक user अपनी bio के रूप में <script>alert(hi)</script> submit करता है, तो Django इसे एक executable script के रूप में नहीं, visible text के रूप में render करता है।
उदाहरण: Auto-Escaping in Templates
By default, every variable rendered with {{ variable }} in a Django template is HTML-escaped. If a user submits <script>alert(hi)</script> as their bio, Django renders it as visible text, not as an executable script.
<!-- templates/profile.html -->
<!-- If comment.text = "<script>alert('hi')</script>" -->
<!-- Django renders it as literal text, not a script -->
<p>{{ comment.text }}</p>
{# Django-only code -- models.py/views.py/urls.py/settings.py
snippets, or template markup using Django template tags/variables
-- can't run standalone via Judge0 or the browser preview, since
it needs a real Django project. Only this course's pure-Python
examples (example_lang == 'python', no Django imports) are
actually runnable, so those still get the button below. #}
safe Filter का Danger
|safe filter Django को बताता है कि एक value पर पूरी तरह भरोसा करे और इसे escaping के बिना raw HTML के रूप में render करे। यह सिर्फ तब safe है जब content पूरी तरह developer द्वारा controlled हो -- कभी user-typed किसी भी चीज़ के लिए नहीं।
|safe apply करना exactly वह hole फिर से खोलता है जिससे auto-escaping protect कर रही थी।उदाहरण: The Danger of the safe Filter
The |safe filter tells Django to trust a value completely and render it as raw HTML without escaping. This is only safe when the content is fully controlled by the developer -- never for anything a user typed.
<!-- Safe: content written by the developer, not a user -->
{{ site_announcement_html|safe }}
<!-- UNSAFE: never do this with user input -->
<!-- {{ comment.text|safe }} -->
{# Django-only code -- models.py/views.py/urls.py/settings.py
snippets, or template markup using Django template tags/variables
-- can't run standalone via Judge0 or the browser preview, since
it needs a real Django project. Only this course's pure-Python
examples (example_lang == 'python', no Django imports) are
actually runnable, so those still get the button below. #}
Python Code में mark_safe
mark_safe() Python से वही काम करता है जो |safe करता है। यह सिर्फ उस HTML को wrap करना चाहिए जो code ने trusted, fixed strings से खुद बनाया हो -- कभी user-submitted text को concatenate करके बनाए गए HTML को नहीं।
उदाहरण: mark_safe in Python Code
mark_safe() does the same thing as |safe but from Python. It should only wrap HTML the code itself built from trusted, fixed strings -- never HTML built by concatenating user-submitted text.
from django.utils.safestring import mark_safe
def build_badge(label):
# label is a fixed, developer-controlled string, not user input
return mark_safe(f'<span class="badge">{label}</span>')
{# Django-only code -- models.py/views.py/urls.py/settings.py
snippets, or template markup using Django template tags/variables
-- can't run standalone via Judge0 or the browser preview, since
it needs a real Django project. Only this course's pure-Python
examples (example_lang == 'python', no Django imports) are
actually runnable, so those still get the button below. #}
- HTML formatting को 'काम' कराने के लिए user-submitted text पर
|safefilter उपयोग करना, जो escaping को पूरी तरह disable करता है। - Template engine को escape करने देने के बजाय Python में user input को string-concatenate करके HTML बनाना।
- यह मान लेना कि XSS सिर्फ एक template problem है और यह भूल जाना कि JSON responses भी unescaped user input carry कर सकती हैं।
- XSS (Cross-Site Scripting) तब होता है जब एक attacker unescaped input के through अपना खुद का script दूसरे user के browser में run करा लेता है।
- Django का template engine default रूप से variables को auto-escape करता है,
<script>को harmless text में बदलते हुए। |safefilter औरmark_safe()escaping को off कर देते हैं, इसलिए इन्हें सिर्फ trusted, developer-written HTML पर उपयोग करें।- User input को कभी raw HTML के रूप में render करने के लिए इतना trust न करें बिना एक अच्छी वजह और एक sanitizer के।
Chapter Quiz — Complete all 9 topics to unlock
0/9 topics done
Complete these topics first: