Eve Templates
String templates
A string with a placeholder is a template. The placeholder {name} puts the value of a variable into the text, written by its type; it holds a name, a literal or a simple expression. A literal brace is written \{ or \}. Formats are explained in Strings.
new name := "Eve";
new count := 3;
print "Hello {name}, you have {count} new orders.";
This is enough for a message, a log line or a file name. It is not safe for HTML: the value is inserted as it is.
new comment := "<script>steal()</script>";
write "<p>{comment}</p>"; ** a script from a user reaches the page: an XSS hole
HTML templates
An HTML template is a file with the extension .evh (or a template literal in the code). A value is written {expression}. Eve escapes it by the place where it stands:
| Place | Example | What the value becomes |
|---|---|---|
| text | <p>{o.customer}</p> | <, > and & are replaced by entities |
| attribute | <a title="{o.note}"> | as text, and the quotes are replaced too |
| URL | <a href="/orders/{o.id}"> | percent-encoded; a scheme such as javascript: is refused |
| script | <script>var id = {o.id};</script> | written as a JSON literal |
** order.evh
<h1>Order {o.id}</h1>
<p class="{o.status}">Customer: {o.customer}</p>
<a href="/orders/{o.id}">details</a>
# a page from a template
driver report is
from "lib" use (html);
process main is
new o := Order(id: 42, customer: "Ann <b>", status: "open");
new page: Html := html.render("order.evh", o: o); ** Html, not String
html.write("out/order42.html", page);
return;
end report;
The Html type
A template file is a value of the type Htmlt (HTML template); rendering it gives an Html. Both belong to the family of data file types, which are loaded in a buffer and traversed in a loop: see Data File Types.
A value of type Html is made only by a template or by html.escape. A function that sends a page accepts Html, not String, so the compiler refuses to send a string that was glued by hand. This is how the rule "text from a user is never code" is checked before the program runs.
Components
A function that returns Html is a component: function card(o: Order) => (@h: Html). A page is a template that calls components; the result of a component is already safe and is not escaped twice.
{for o in orders}?); and the module name are open.report.evh, write out/report.html.Html.{expr} without escaping, and a type Text?Read next: Networking