﻿id	summary	reporter	owner	description	type	status	component	version	severity	resolution	keywords	cc	stage	has_patch	needs_docs	needs_tests	needs_better_patch	easy	ui_ux
37262	Form media given as html-safe strings rendered as paths on 6.1	Adam Johnson	Adam Johnson	"Since #29490 (Django 4.1), `Media` assets may be given as hashable objects implementing `__html__()`, rendered verbatim as the complete tag, per the old [https://docs.djangoproject.com/en/5.1/topics/forms/media/#paths-as-objects ""Paths as objects"" docs section].
Html-safe strings from `mark_safe()` satisfy that contract, but since 8096b5251090bf7539c59956e398b027c7525529 (#37085) they are treated as static file paths instead: `Media.__init__()` now normalizes every `isinstance(path, str)` entry into `Script`/`Stylesheet`, and `SafeString` is a `str` subclass, so e.g. `forms.Media(js=[mark_safe('<script defer src=""https://example.org/asset.js""></script>')])`
renders as`<script src=""/static/%3Cscript%20defer%20src%3D%22https%3A/...""></script>` rather than the tag verbatim as in 6.0. The same happens for `css` entries but non-str `@html_safe` classes still work.

The fix is to skip normalization for any string that provides `__html__()`, so that they take the pre-existing verbatim rendering branch."	Bug	assigned	Forms	6.1	Normal				Unreviewed	1	0	0	0	0	0
