Maud: Compile-time HTML templates for Rust
github.com
github.com
>Why doesn't Maud implement context-aware escaping?
>If a project follows best practices in separating HTML and CSS/JavaScript, then context-aware escaping is unnecessary.
>Google uses context-aware escaping because it has a large, decades-old code base, much of it written before these best practices were well known. Any project that uses Maud is neither large nor decades-old, and so should not have the need for this feature.
This seems misguided. Javascript and CSS are not the only contexts. Another example is URIs (which can be javascript: or data:), which Golang's html/template correctly escapes: https://github.com/golang/go/blob/master/src/html/template/u...
I'd also like to emphasize that no Rust template engine – that I'm aware of – does context-aware escaping. At least Maud has it on the roadmap.
But if someone's publishing a HTML templating system, and they don't have enough knowledge about HTML to understand the need for contextual escaping, I would have grave concerns about the Dunning-Kruger effect & the quality of any software that engineer writes.
I think a better way of terming this would be that you have concern the the author might not have enough domain expertise, which is very different than being incompetent.
This gives me pause that Maud isn't right for a production system at this time, but is that so surprising for a 0.11 library?
I guess what I was more getting at was the thought process that goes "I'm going to develop and release a library in X domain", when ones knowledge of said domain is low. And then launching said library before one has really gained a lot of knowledge of that domain.
Yes, I am saying that you should never use <a href="javascript:void 0"> or similar. (<a href="#"> is illegitimate in most cases, but is occasionally used honestly to cause scrolling to the top of the page.)
Buttons aren't perfect, either, you have to write additional code to handle middle-click actions, and the right-click menu doesn't contain the expected "Open in New Tab" or "Copy Link Location".
I prefer to use buttons to affect the state of the current page. And use anchor tags for all other navigation, even if I'm handling it with .addEventListener("click", ...).
I suppose I could just hide the non-functional links, or add them dynamically with javascript. But that could affect layout.
Still, your solution is nicer in many ways, thanks.
But yeah, stylesheets might need adjustment for best results if you want to keep it on-screen even when it’s not operative, e.g. add a class link-needs-js which you style along with your :link, :visited.
In the hidden versus disabled thing, I do approximately this, if I have functionality that can’t work without JS (for whatever reason): if it’s completely optional, I hide it; if it’s important, I show it with a disabled style including not-allowed cursor (the disabled attribute if it’s a button, or a class if it’s an anchor) and some kind of “JS required” title, to at least give a hint as to why it’s not working and what the user must to do make it work. Anything between those extremes, I decide on a case-by-case basis, being influenced also by what else is there and does work.
Oh well.
Probably a few others I'm not aware of.