Skip to content

Commit

Permalink
Fix Jinja2 template rendering with autoescape enabled (#690)
Browse files Browse the repository at this point in the history
* add autoescape true

* Update initial_commit.py with space

* Update initial_commit.py

Add autoescape=True to avoid XSS
  • Loading branch information
sujay0412 authored Apr 5, 2024
1 parent e02ccae commit 74e88b8
Show file tree
Hide file tree
Showing 2 changed files with 2 additions and 2 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -510,7 +510,7 @@ def get_files_to_commit(directory_path: Path) -> List[FileToCommit]:
def create_adf_config_file(props: CustomResourceProperties) -> FileToCommit:
template = HERE / "adfconfig.yml.j2"
adf_config = (
jinja2.Template(template.read_text(), undefined=jinja2.StrictUndefined)
jinja2.Template(template.read_text(), undefined=jinja2.StrictUndefined , autoescape=True)
.render(vars(props))
.encode()
)
Expand Down
2 changes: 1 addition & 1 deletion src/lambda_codebase/initial_commit/initial_commit.py
Original file line number Diff line number Diff line change
Expand Up @@ -555,7 +555,7 @@ def create_adf_config_file(
) -> FileToCommit:
template = HERE / input_file_name
adf_config = (
jinja2.Template(template.read_text(), undefined=jinja2.StrictUndefined)
jinja2.Template(template.read_text(), undefined=jinja2.StrictUndefined, autoescape=True)
.render(vars(props))
.encode()
)
Expand Down

0 comments on commit 74e88b8

Please sign in to comment.