Filters: Escaping and Encoding
Filters
escape / e
Escapes a string for safe output:
escape / e
{{ user_input|escape }}
{{ user_input|e }}
{{ value|e('html') }}
{{ value|e('html_attr') }}
{{ value|e('js') }}
{{ value|e('css') }}
{{ value|e('url') }}
raw
Disables escaping for a value:
raw
{{ trusted_html|raw }}
caution
Use raw only for trusted content.
raw vs escape
- {{ user_input|raw }}
+ {{ user_input|escape }}
+ {{ trusted_html|raw }}
url_encode
Encodes a string for use in a URL:
url_encode
{{ 'hello world'|url_encode }}
{# hello%20world #}
{{ {name: 'John', age: 30}|url_encode }}
{# name=John&age=30 #}
json_encode
Encodes data as JSON:
json_encode
{{ data|json_encode }}
{{ data|json_encode(constant('JSON_PRETTY_PRINT')) }}
default
Default value if the variable is undefined or empty:
default
{{ user.name|default('Anonymous') }}
{{ title|default('Untitled') }}
{{ items|default([]) }}