Opened 28 hours ago

Last modified 28 hours ago

#37262 assigned Bug

Form media given as html-safe strings rendered as paths on 6.1

Reported by: Adam Johnson Owned by: Adam Johnson
Component: Forms Version: 6.1
Severity: Normal Keywords:
Cc: Triage Stage: Unreviewed
Has patch: yes Needs documentation: no
Needs tests: no Patch needs improvement: no
Easy pickings: no UI/UX: no

Description (last modified by Adam Johnson)

Since #29490 (Django 4.1), Media assets may be given as hashable objects implementing __html__(), rendered verbatim as the complete tag, per the old "Paths as objects" docs section.
Html-safe strings from mark_safe() satisfy that contract, but since 8096b5251090bf7539c59956e398b027c7525529 (#37085) they are treated as static file paths instead: Media.__init__() now normalizes every isinstance(path, str) entry into Script/Stylesheet, and SafeString is a str subclass, so e.g. forms.Media(js=[mark_safe('<script defer src="https://example.org/asset.js"></script>')])
renders as<script src="/static/%3Cscript%20defer%20src%3D%22https%3A/..."></script> rather than the tag verbatim as in 6.0. The same happens for css entries but non-str @html_safe classes still work.

The fix is to skip normalization for any string that provides __html__(), so that they take the pre-existing verbatim rendering branch.

Change History (1)

comment:1 by Adam Johnson, 28 hours ago

Description: modified (diff)
Note: See TracTickets for help on using tickets.
Back to Top