Expand description
The one thing the two minijinja environments in this crate share: how a
template is found.
notify renders .j2 messages and
webadmin::pages renders .html pages, and the
two had byte-identical loader closures โ check template_dir for a file of
this name, fall back to the compiled-in default โ differing only in which
table they closed over.
Sharing the loader cannot weaken the escaping rule, which is worth
stating because it is a security control: minijinja picks auto-escaping off
the template name, so account/_card.html escapes and
webhook/certificate_issued.j2 does not. That decision is made by the
extension in the name, never by the loader, and
auto_escaping_is_on_for_pages_and_off_for_notify pins both directions. A
page template renamed .j2 would turn an account contact or an EAB label
into stored XSS โ which is a rule about naming, and this function cannot
affect it either way.
Functionsยง
- loader_
env - An environment that resolves a template name to a
template_dirfile first and the compiled-in default second.