Make text safe for an output context: HTML, HTML attributes, JSON strings.
| I want... | Use |
|---|---|
| HTML text or attribute | escape.HTML(s) |
| JSON string | escape.JSON(b, s) |
Old (webtyp.com/fmt) |
New (webtyp.com/escape) |
|---|---|
fmt.Convert(s).EscapeHTML() |
escape.HTML(s) |
fmt.Convert(s).EscapeAttr() |
escape.HTML(s) |
fmt.JSONEscape(s, b) |
escape.JSON(b, s) |
fmt.Html(format, args...) |
fmt.Sprintf(format, args...) |
escape.HTML(s) does NOT make text safe for URLs, JS or CSS contexts. It only protects against injections within standard HTML text elements or within HTML attributes quoted with single or double quotes.