-HarryVon: thorsteneilers via Lucee [mailto:lucee@googlegroups.com]
Gesendet: Montag, 11. April 2016 10:28
An: Lucee lucee@googlegroups.com
Betreff: [Lucee] Use ESAPIEncode() or EncodeForHTML() in Lucee 4.5 vs. Lucee 5?
Hi,
at the moment I use XMLFormat() to encode user output in my views on Lucee 4.5.
Would it be better to user ESAPIEncode(‘HTML’,string) in Lucee 4.5, because EncodeForHTML() is deprecated?
But what’s recommended for Lucee 5? I read somewhere EncodeForHTML() will be reactivated in Lucee 5?
Confused.
it would be nice to have a less verbose shortcut like underscore templates
i.e. <%=output_var_unescaped %> and <%-output_var_escaped %>
for traditional CFML with #'sOn Mon, Apr 11, 2016 at 6:30 PM, Harry Klein <@Harry_Klein> wrote:
Von: thorsteneilers via Lucee [mailto:lucee@googlegroups.com] Gesendet: Montag, 11. April 2016 10:28 An: Lucee lucee@googlegroups.com Betreff: [Lucee] Use ESAPIEncode() or EncodeForHTML() in Lucee 4.5 vs.
Lucee 5?
Hi,
at the moment I use XMLFormat() to encode user output in my views on Lucee
4.5.
Would it be better to user ESAPIEncode(‘HTML’,string) in Lucee 4.5,
because EncodeForHTML() is deprecated?
Wouldn’t CFML be less verbose as you can use as few cfoutput blocks as you
like?
For example, in my CMS detail template I have just one cfoutput block with
up to 15 variables that just have # surrounding it.
MD> On 13 Apr 2016, at 16:03, Brad Wood <@Brad_Wood> wrote:
FYI ACF2016 has added are there any plans for supporting this in Lucee?
Nice feature, I hadn’t heard about that one. Someone just needs to put in a ticket for it. What will be cool is that on Lucee, you could set that to be your default for the cfoutput tag if you wished in Application.cfc.
FYI ACF2016 has added are there any plans for
supporting this in Lucee?
Nice feature, I hadn’t heard about that one. Someone just needs to put in
a ticket for it. What will be cool is that on Lucee, you could set that to
be your default for the cfoutput tag if you wished in Application.cfc.