my $page=$params{page};
delete $params{page};
+ eval q{use CGI 'escapeHTML'};
+
if ($key eq 'link') {
if (%params) {
$meta{$page}='' unless exists $meta{$page};
- $meta{$page}.="<link href=\"$value\" ".
- join(" ", map { "$_=\"$params{$_}\"" } keys %params).
+ $meta{$page}.="<link href=\"".escapeHTML($value)."\" ".
+ join(" ", map { escapeHTML("$_=\"$params{$_}\"") } keys %params).
" />\n";
}
else {
}
}
elsif ($key eq 'title') {
- $title{$page}=$value;
+ $title{$page}=escapeHTML($value);
}
else {
$meta{$page}='' unless exists $meta{$page};
- $meta{$page}.="<meta name=\"$key\" content=\"$value\" />\n";
+ $meta{$page}.="<meta name=\"".escapeHTML($key)."\" content=\"".escapeHTML($value)."\" />\n";
}
return "";
This plugin allows inserting arbitrary metadata into the source of a page.
+This plugin is not enabled by default. If it is enabled, the title of this
+page will say it is. [[meta title="meta plugin (enabled)"]]
Enter the metadata as follows:
\\[[meta field="value"]]
If the field is not treated specially (as the link and title fields are),
the metadata will be written to the generated html page as a <meta>
header.
-
-This plugin is not enabled by default. If it is enabled, the title of this
-page will say it is.
-[[meta title="meta plugin (enabled)"]]
make arbitrary changes. The function is passed named parameters `page` and
`content` and should return the filtered content.
-## sanitize
-
- IkiWiki::hook(type => "filter", id => "foo", call => \&sanitize);
-
-Use this to implement html sanitization or anything else that needs to
-modify the content of a page after it has been fully converted to html.
-The function is passed the page content and should return the sanitized
-content.
-
## pagetemplate
IkiWiki::hook(type => "pagetemplate", id => "foo", call => \&pagetemplate);
common thing to do is probably to call $template->param() to add a new
custom parameter to the template.
+## sanitize
+
+ IkiWiki::hook(type => "sanitize", id => "foo", call => \&sanitize);
+
+Use this to implement html sanitization or anything else that needs to
+modify the content of a page after it has been fully converted to html.
+The function is passed the page content and should return the sanitized
+content.
+
## delete
IkiWiki::hook(type => "delete", id => "foo", call => \&dele);