Skip to content
Gx
GitHub

GX7001: conversion to gx.SafeHTML needs //gx:trusted

A value that is not a constant is changed to gx.SafeHTML.

Cause

A value that is not a constant is changed to gx.SafeHTML. Gx writes gx.SafeHTML without escaping, so text from a user can put a script in the page.

Example

shop/render.go
package shop

import "github.com/alternayte/gx"

// Body returns the HTML of a comment that a user wrote.
func Body(comment string) gx.SafeHTML {
	return gx.SafeHTML(comment)
}

gx lint reports:

gx lint
shop/render.go:7:9: GX7001: conversion to gx.SafeHTML needs //gx:trusted <reason>

Fix

  1. Do not change user text to gx.SafeHTML. Gx escapes a string.
  2. When the HTML comes from a source that you trust, add //gx:trusted <reason> on the same line.