Port templates to NodeBB 4.14 benchpress escaping
NodeBB 4.14 registers a real __escape for template rendering (4.13 used
identity), so raw-HTML output must use the double-brace forms:
- HTML helpers: {{buildAvatar(...)}}, {{buildCategoryIcon(...)}}, etc.
- Pre-rendered HTML fields: {{txEscape(content)}} / {{./descriptionParsed}}
- Token-bearing text (nav labels, category names): {{tx(...)}}
- emails/partials/post-queue-body.tpl also adopts the 4.14 data shape
(notification.category/topic/user/content).
Mirrors the harmony 2.2.72 -> 3.0.15 and core 4.13.2 -> 4.14.0 diffs.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -3,7 +3,7 @@
|
||||
{{{ if !./isSection }}}
|
||||
<li data-cid="{./cid}" class="category-children-item small {./class}">
|
||||
<div class="westgate-category-child d-flex gap-1">
|
||||
{buildCategoryIcon(@value, "18px", "westgate-child-icon rounded-1")}
|
||||
{{buildCategoryIcon(@value, "18px", "westgate-child-icon rounded-1")}}
|
||||
<a href="{{{ if ./link }}}{./link}{{{ else }}}{config.relative_path}/category/{./slug}{{{ end }}}" class="text-reset fw-semibold flex-1">{./name}</a>
|
||||
</div>
|
||||
</li>
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
|
||||
<div class="d-flex col-lg-7 gap-2 gap-lg-3">
|
||||
<div class="flex-shrink-0">
|
||||
{buildCategoryIcon(@value, "40px", "rounded-1")}
|
||||
{{buildCategoryIcon(@value, "40px", "rounded-1")}}
|
||||
</div>
|
||||
<div class="flex-grow-1 d-flex flex-wrap gap-1 me-0 me-lg-2">
|
||||
<h2 class="title text-break fs-4 fw-semibold m-0 tracking-tight w-100">
|
||||
@@ -11,7 +11,7 @@
|
||||
</h2>
|
||||
{{{ if ./descriptionParsed }}}
|
||||
<div class="description text-muted text-sm w-100 line-clamp-sm-5">
|
||||
{./descriptionParsed}
|
||||
{{./descriptionParsed}}
|
||||
</div>
|
||||
{{{ end }}}
|
||||
{{{ if !./link }}}
|
||||
|
||||
@@ -3,12 +3,12 @@
|
||||
{{{ if @first }}}
|
||||
<div component="category/posts" class="ps-2 text-xs d-flex flex-column h-100 gap-1">
|
||||
<div class="text-nowrap text-truncate">
|
||||
<a class="text-decoration-none avatar-tooltip" title="{./user.displayname}" href="{config.relative_path}/user/{./user.userslug}">{buildAvatar(posts.user, "18px", true)}</a>
|
||||
<a class="text-decoration-none avatar-tooltip" title="{./user.displayname}" href="{config.relative_path}/user/{./user.userslug}">{{buildAvatar(posts.user, "18px", true)}}</a>
|
||||
<a class="permalink text-muted timeago text-xs" href="{config.relative_path}/topic/{./topic.slug}{{{ if ./index }}}/{./index}{{{ end }}}" title="{./timestampISO}" aria-label="[[global:lastpost]]"></a>
|
||||
</div>
|
||||
<div class="post-content text-xs text-break line-clamp-sm-2 lh-sm position-relative flex-fill">
|
||||
<a class="stretched-link" tabindex="-1" href="{config.relative_path}/topic/{./topic.slug}{{{ if ./index }}}/{./index}{{{ end }}}" aria-label="[[global:lastpost]]"></a>
|
||||
{./content}
|
||||
{{txEscape(./content)}}
|
||||
</div>
|
||||
</div>
|
||||
{{{ end }}}
|
||||
|
||||
Reference in New Issue
Block a user