Commit 29014268 authored by Georg Brandl's avatar Georg Brandl

Merged revisions 83599 via svnmerge from

svn+ssh://pythondev@svn.python.org/python/branches/py3k

........
  r83599 | georg.brandl | 2010-08-02 23:51:18 +0200 (Mo, 02 Aug 2010) | 1 line

  #9061: warn that single quotes are never escaped.
........
parent 3db92e94
...@@ -349,10 +349,13 @@ algorithms implemented in this module in other circumstances. ...@@ -349,10 +349,13 @@ algorithms implemented in this module in other circumstances.
Convert the characters ``'&'``, ``'<'`` and ``'>'`` in string *s* to HTML-safe Convert the characters ``'&'``, ``'<'`` and ``'>'`` in string *s* to HTML-safe
sequences. Use this if you need to display text that might contain such sequences. Use this if you need to display text that might contain such
characters in HTML. If the optional flag *quote* is true, the quotation mark characters in HTML. If the optional flag *quote* is true, the quotation mark
character (``'"'``) is also translated; this helps for inclusion in an HTML character (``"``) is also translated; this helps for inclusion in an HTML
attribute value, as in ``<A HREF="...">``. If the value to be quoted might attribute value delimited by double quotes, as in ``<a href="...">``. Note
include single- or double-quote characters, or both, consider using the that single quotes are never translated.
:func:`quoteattr` function in the :mod:`xml.sax.saxutils` module instead.
If the value to be quoted might include single- or double-quote characters,
or both, consider using the :func:`quoteattr` function in the
:mod:`xml.sax.saxutils` module instead.
.. _cgi-security: .. _cgi-security:
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment