▲ | itishappy 8 days ago | |
You're just handing off responsibility for sanitization to the user instead of the library author. With t-strings the rendering function is responsible for sanitization, and users can pass unrendered templates to it. With f-strings there's no concept of an unrendered template, it just immediately becomes a string. Whoever is creating the template therefore has to be careful what they put in it. |