Eve Templates

A template is a text with holes: a fixed form that is filled with values. Eve has two kinds. The string templates exist today: they put values into a message. The HTML templates are planned for the web (version 0.6): they build a page, and escape every value so that text from a user can never become code.

String templates

A string with a placeholder is a template. The placeholder {name} puts the value of a variable into the text, written by its type; it holds a name, a literal or a simple expression. A literal brace is written \{ or \}. Formats are explained in Strings.


new name := "Eve";
new count := 3;
print "Hello {name}, you have {count} new orders.";

This is enough for a message, a log line or a file name. It is not safe for HTML: the value is inserted as it is.


new comment := "<script>steal()</script>";
write "<p>{comment}</p>";     ** a script from a user reaches the page: an XSS hole

HTML templates

Proposed, planned for 0.6. The names and forms below are a proposal for the author's review (Q-027).

An HTML template is a file with the extension .evh (or a template literal in the code). A value is written {expression}. Eve escapes it by the place where it stands:

PlaceExampleWhat the value becomes
text<p>{o.customer}</p><, > and & are replaced by entities
attribute<a title="{o.note}">as text, and the quotes are replaced too
URL<a href="/orders/{o.id}">percent-encoded; a scheme such as javascript: is refused
script<script>var id = {o.id};</script>written as a JSON literal

** order.evh
<h1>Order {o.id}</h1>
<p class="{o.status}">Customer: {o.customer}</p>
<a href="/orders/{o.id}">details</a>

# a page from a template
driver report is
  from "lib" use (html);
  process main is
    new o := Order(id: 42, customer: "Ann <b>", status: "open");
    new page: Html := html.render("order.evh", o: o);   ** Html, not String
    html.write("out/order42.html", page);
  return;
end report;

The Html type

A template file is a value of the type Htmlt (HTML template); rendering it gives an Html. Both belong to the family of data file types, which are loaded in a buffer and traversed in a loop: see Data File Types.

A value of type Html is made only by a template or by html.escape. A function that sends a page accepts Html, not String, so the compiler refuses to send a string that was glued by hand. This is how the rule "text from a user is never code" is checked before the program runs.

Components

A function that returns Html is a component: function card(o: Order) => (@h: Html). A page is a template that calls components; the result of a component is already safe and is not escaped twice.

Not designed yet. Templates as separate files, as literals in the code, or both; the file extension; the syntax of loops and conditions inside a template ({for o in orders}?); and the module name are open.
TODO: answer Q-027 (decision_level7.md) and write the example "daily report" for the data client: read the orders, fill report.evh, write out/report.html.
TODO: add a table with the escaping contexts that are not in the first version (CSS, a JavaScript string, an HTML comment) and the rule for a value that is already Html.
TODO: write the XSS test suite described in the version map: the templates must pass it before 0.6.
TODO: plain text and e-mail templates: the same {expr} without escaping, and a type Text?

Read next: Networking