← Back to Django Course | Chapter 15: Security, Caching & Deployment | Lesson 4 of 9

Django में XSS Protection

XSS protection Django का यह double-check करने जैसा है कि visitor द्वारा type किया गया कोई भी text page पर वापस दिखाने से पहले secretly एक sneaky script तो नहीं है।
Syntax
markup
{{ variable }}         <!-- escaped automatically: safe -->
{{ variable|safe }}    <!-- rendered as raw HTML: only for trusted content -->

Templates में Auto-Escaping

Default रूप से, Django template में {{ variable }} से render होने वाली हर variable HTML-escaped होती है। अगर एक user अपनी bio के रूप में <script>alert(hi)</script> submit करता है, तो Django इसे एक executable script के रूप में नहीं, visible text के रूप में render करता है।

Note: Auto-escaping पूरे project के लिए default रूप से on है -- इसे पाने के लिए आपको कुछ करने की ज़रूरत नहीं।

उदाहरण: Auto-Escaping in Templates

By default, every variable rendered with {{ variable }} in a Django template is HTML-escaped. If a user submits <script>alert(hi)</script> as their bio, Django renders it as visible text, not as an executable script.

markup
<!-- templates/profile.html -->
<!-- If comment.text = "<script>alert('hi')</script>" -->
<!-- Django renders it as literal text, not a script -->
<p>{{ comment.text }}</p>
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}

safe Filter का Danger

|safe filter Django को बताता है कि एक value पर पूरी तरह भरोसा करे और इसे escaping के बिना raw HTML के रूप में render करे। यह सिर्फ तब safe है जब content पूरी तरह developer द्वारा controlled हो -- कभी user-typed किसी भी चीज़ के लिए नहीं।

Warning: User-submitted content पर |safe apply करना exactly वह hole फिर से खोलता है जिससे auto-escaping protect कर रही थी।

उदाहरण: The Danger of the safe Filter

The |safe filter tells Django to trust a value completely and render it as raw HTML without escaping. This is only safe when the content is fully controlled by the developer -- never for anything a user typed.

markup
<!-- Safe: content written by the developer, not a user -->
{{ site_announcement_html|safe }}

<!-- UNSAFE: never do this with user input -->
<!-- {{ comment.text|safe }} -->
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}

Python Code में mark_safe

mark_safe() Python से वही काम करता है जो |safe करता है। यह सिर्फ उस HTML को wrap करना चाहिए जो code ने trusted, fixed strings से खुद बनाया हो -- कभी user-submitted text को concatenate करके बनाए गए HTML को नहीं।

उदाहरण: mark_safe in Python Code

mark_safe() does the same thing as |safe but from Python. It should only wrap HTML the code itself built from trusted, fixed strings -- never HTML built by concatenating user-submitted text.

markup
from django.utils.safestring import mark_safe

def build_badge(label):
    # label is a fixed, developer-controlled string, not user input
    return mark_safe(f'<span class="badge">{label}</span>')
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}
Related Topics
{# common_mistakes/chapter_summary/browser_support: on Hindi pages the view already swaps in the hi_ translation fields (or blanks these out if untranslated), so this renders correctly for both languages without a lang_code check here. #}
आम गलतियां
  1. HTML formatting को 'काम' कराने के लिए user-submitted text पर |safe filter उपयोग करना, जो escaping को पूरी तरह disable करता है।
  2. Template engine को escape करने देने के बजाय Python में user input को string-concatenate करके HTML बनाना।
  3. यह मान लेना कि XSS सिर्फ एक template problem है और यह भूल जाना कि JSON responses भी unescaped user input carry कर सकती हैं।
चैप्टर सारांश
  • XSS (Cross-Site Scripting) तब होता है जब एक attacker unescaped input के through अपना खुद का script दूसरे user के browser में run करा लेता है।
  • Django का template engine default रूप से variables को auto-escape करता है, <script> को harmless text में बदलते हुए।
  • |safe filter और mark_safe() escaping को off कर देते हैं, इसलिए इन्हें सिर्फ trusted, developer-written HTML पर उपयोग करें।
  • User input को कभी raw HTML के रूप में render करने के लिए इतना trust न करें बिना एक अच्छी वजह और एक sanitizer के।

Login to run this code

C/C++/Java/PHP execution requires a free account. Your code is saved — you'll land right back in the editor after logging in.