GX7001: conversion to gx.SafeHTML needs //gx:trusted
A value that is not a constant is changed to gx.SafeHTML.
Cause
A value that is not a constant is changed to gx.SafeHTML. Gx writes gx.SafeHTML without escaping, so text from a user can put a script in the page.
Example
package shop
import "github.com/alternayte/gx"
// Body returns the HTML of a comment that a user wrote.
func Body(comment string) gx.SafeHTML {
return gx.SafeHTML(comment)
}gx lint reports:
shop/render.go:7:9: GX7001: conversion to gx.SafeHTML needs //gx:trusted <reason>Fix
- Do not change user text to
gx.SafeHTML. Gx escapes a string. - When the HTML comes from a source that you trust, add
//gx:trusted <reason>on the same line.