Re: formencode.htmlfill.FillingParser chokes on javascript HTML

Ian Bicking <[email protected]> Wed, 18 Nov 2009 14:49:44 -0600
Newsgroups gmane.comp.python.formencode
Message-ID <[email protected]>
On Wed, Nov 18, 2009 at 2:40 PM, Roy Hyunjin Han
<[email protected]> wrote:
>
> Hi,
>
> I am using formencode.htmlfill() to render a form, but the function is inadvertently parsing my javascript code.  Specifically, formencode.htmlfill.FillingParser raises the following exception
>
>     HTMLParseError: malformed start tag
>
> when it encounters the following jQuery code
>
>     function hover(obj, text) {$(obj).append("<span class=flag> (" + text + ")</span>");}
>
> and does not raise the exception after I remove the offending code.  Perhaps we should strip javascript before htmlfill?

Well... what needs to happen is everything between <script> and
</script> should be treated as text, but HTMLParser doesn't understand
that.

I *think* it would work fine to do:

  function hover(obj, text) {$(obj).append("&lt;span class=flag&gt; ("
+ text + ")&lt;/span&gt;");}

Which is actually something we could do automatically with a regex.
Unfortunately right now I can't reproduce, I put a test at the bottom
here: http://bitbucket.org/ianb/formencode/src/tip/tests/test_htmlfill.py
-- but it passes.

--
Ian Bicking  |  http://blog.ianbicking.org  |  http://topplabs.org/civichacker

------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
trial. Simplify your report design, integration and deployment - and focus on 
what you do best, core application coding. Discover what's new with
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
_______________________________________________
FormEncode-discuss mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/formencode-discuss