🐛 (locale): Corrige escapado de L10n::using()
`L10n::using()` insertaba el texto de `L10n::n()` sin escapar, tratándolo igual que una traducción de confianza (`l()`/`t()`); ahora se escapa como cualquier otro valor interpolado con `html!`. Además, `using()` no debe usarse en valores de atributo. Su marcado de confianza para `l()`/`t()` podría romper el delimitador si la traducción contuviera una comilla. Se sustituye por `lookup()`
This commit is contained in:
parent
6bea4a5793
commit
3198b74399
13 changed files with 96 additions and 26 deletions
|
|
@ -60,3 +60,28 @@ async fn check_unknown_key() {
|
|||
let translation = l10n.lookup(&Locale::resolve("en-US"));
|
||||
assert_eq!(translation, None);
|
||||
}
|
||||
|
||||
// `using()` renders literal text (`L10n::n()`) as HTML-escaped `Markup`, because it may come from
|
||||
// runtime data (e.g. a menu title or a role label) rather than developer-authored content.
|
||||
#[pagetop::test]
|
||||
async fn literal_text_is_escaped_when_rendered_as_markup() {
|
||||
setup().await;
|
||||
|
||||
let l10n = L10n::n("<script>alert(1)</script>");
|
||||
let markup = l10n.using(&Locale::default());
|
||||
assert_eq!(
|
||||
markup.into_string(),
|
||||
"<script>alert(1)</script>"
|
||||
);
|
||||
}
|
||||
|
||||
// Translation keys (`L10n::l()`/`L10n::t()`) are developer-authored `.ftl` content that may embed
|
||||
// HTML on purpose (e.g. `<strong>`), so `using()` must keep rendering them unescaped.
|
||||
#[pagetop::test]
|
||||
async fn translated_text_is_not_escaped_when_rendered_as_markup() {
|
||||
setup().await;
|
||||
|
||||
let l10n = L10n::l("test_hello_world");
|
||||
let markup = l10n.using(&Locale::resolve("en-US"));
|
||||
assert_eq!(markup.into_string(), "Hello world!");
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue