Skip to main content

Module templating

Module templating 

Source
Expand description

The one thing the two minijinja environments in this crate share: how a template is found.

notify renders .j2 messages and webadmin::pages renders .html pages, and the two had byte-identical loader closures โ€” check template_dir for a file of this name, fall back to the compiled-in default โ€” differing only in which table they closed over.

Sharing the loader cannot weaken the escaping rule, which is worth stating because it is a security control: minijinja picks auto-escaping off the template name, so account/_card.html escapes and webhook/certificate_issued.j2 does not. That decision is made by the extension in the name, never by the loader, and auto_escaping_is_on_for_pages_and_off_for_notify pins both directions. A page template renamed .j2 would turn an account contact or an EAB label into stored XSS โ€” which is a rule about naming, and this function cannot affect it either way.

Functionsยง

loader_env
An environment that resolves a template name to a template_dir file first and the compiled-in default second.