templates.txt 23 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656
  1. ============================
  2. The Django template language
  3. ============================
  4. .. admonition:: About this document
  5. This document explains the language syntax of the Django template system. If
  6. you're looking for a more technical perspective on how it works and how to
  7. extend it, see :doc:`/ref/templates/api`.
  8. Django's template language is designed to strike a balance between power and
  9. ease. It's designed to feel comfortable to those used to working with HTML. If
  10. you have any exposure to other text-based template languages, such as Smarty_
  11. or CheetahTemplate_, you should feel right at home with Django's templates.
  12. .. admonition:: Philosophy
  13. If you have a background in programming, or if you're used to languages
  14. like PHP which mix programming code directly into HTML, you'll want to
  15. bear in mind that the Django template system is not simply Python embedded
  16. into HTML. This is by design: the template system is meant to express
  17. presentation, not program logic.
  18. The Django template system provides tags which function similarly to some
  19. programming constructs -- an :ttag:`if` tag for boolean tests, a :ttag:`for`
  20. tag for looping, etc. -- but these are not simply executed as the
  21. corresponding Python code, and the template system will not execute
  22. arbitrary Python expressions. Only the tags, filters and syntax listed below
  23. are supported by default (although you can add :doc:`your own extensions
  24. </howto/custom-template-tags>` to the template language as needed).
  25. .. _`The Django template language: For Python programmers`: ../templates_python/
  26. .. _Smarty: http://smarty.php.net/
  27. .. _CheetahTemplate: http://www.cheetahtemplate.org/
  28. Templates
  29. =========
  30. .. highlightlang:: html+django
  31. A template is simply a text file. It can generate any text-based format (HTML,
  32. XML, CSV, etc.).
  33. A template contains **variables**, which get replaced with values when the
  34. template is evaluated, and **tags**, which control the logic of the template.
  35. Below is a minimal template that illustrates a few basics. Each element will be
  36. explained later in this document.::
  37. {% extends "base_generic.html" %}
  38. {% block title %}{{ section.title }}{% endblock %}
  39. {% block content %}
  40. <h1>{{ section.title }}</h1>
  41. {% for story in story_list %}
  42. <h2>
  43. <a href="{{ story.get_absolute_url }}">
  44. {{ story.headline|upper }}
  45. </a>
  46. </h2>
  47. <p>{{ story.tease|truncatewords:"100" }}</p>
  48. {% endfor %}
  49. {% endblock %}
  50. .. admonition:: Philosophy
  51. Why use a text-based template instead of an XML-based one (like Zope's
  52. TAL)? We wanted Django's template language to be usable for more than
  53. just XML/HTML templates. At World Online, we use it for emails,
  54. JavaScript and CSV. You can use the template language for any text-based
  55. format.
  56. Oh, and one more thing: Making humans edit XML is sadistic!
  57. Variables
  58. =========
  59. Variables look like this: ``{{ variable }}``. When the template engine
  60. encounters a variable, it evaluates that variable and replaces it with the
  61. result. Variable names consist of any combination of alphanumeric characters
  62. and the underscore (``"_"``). The dot (``"."``) also appears in variable
  63. sections, although that has a special meaning, as indicated below.
  64. Importantly, *you cannot have spaces or punctuation characters in variable
  65. names.*
  66. Use a dot (``.``) to access attributes of a variable.
  67. .. admonition:: Behind the scenes
  68. Technically, when the template system encounters a dot, it tries the
  69. following lookups, in this order:
  70. * Dictionary lookup
  71. * Attribute lookup
  72. * Method call
  73. * List-index lookup
  74. In the above example, ``{{ section.title }}`` will be replaced with the
  75. ``title`` attribute of the ``section`` object.
  76. If you use a variable that doesn't exist, the template system will insert
  77. the value of the ``TEMPLATE_STRING_IF_INVALID`` setting, which is set to ``''``
  78. (the empty string) by default.
  79. Filters
  80. =======
  81. You can modify variables for display by using **filters**.
  82. Filters look like this: ``{{ name|lower }}``. This displays the value of the
  83. ``{{ name }}`` variable after being filtered through the ``lower`` filter,
  84. which converts text to lowercase. Use a pipe (``|``) to apply a filter.
  85. Filters can be "chained." The output of one filter is applied to the next.
  86. ``{{ text|escape|linebreaks }}`` is a common idiom for escaping text contents,
  87. then converting line breaks to ``<p>`` tags.
  88. Some filters take arguments. A filter argument looks like this: ``{{
  89. bio|truncatewords:30 }}``. This will display the first 30 words of the ``bio``
  90. variable.
  91. Filter arguments that contain spaces must be quoted; for example, to join a list
  92. with commas and spaced you'd use ``{{ list|join:", " }}``.
  93. Django provides about thirty built-in template filters. You can read all about
  94. them in the :ref:`built-in filter reference <ref-templates-builtins-filters>`.
  95. To give you a taste of what's available, here are some of the more commonly used
  96. template filters:
  97. :tfilter:`default`
  98. If a variable is false or empty, use given default. Otherwise, use the
  99. value of the variable
  100. For example::
  101. {{ value|default:"nothing" }}
  102. If ``value`` isn't provided or is empty, the above will display
  103. "``nothing``".
  104. :tfilter:`length`
  105. Returns the length of the value. This works for both strings and lists;
  106. for example::
  107. {{ value|length }}
  108. If ``value`` is ``['a', 'b', 'c', 'd']``, the output will be ``4``.
  109. :tfilter:`striptags`
  110. Strips all [X]HTML tags. For example::
  111. {{ value|striptags }}
  112. If ``value`` is ``"<b>Joel</b> <button>is</button> a
  113. <span>slug</span>"``, the output will be ``"Joel is a slug"``.
  114. Again, these are just a few examples; see the :ref:`built-in filter reference
  115. <ref-templates-builtins-filters>` for the complete list.
  116. You can also create your own custom template filters; see
  117. :doc:`/howto/custom-template-tags`.
  118. .. seealso::
  119. Django's admin interface can include a complete reference of all template
  120. tags and filters available for a given site. See
  121. :doc:`/ref/contrib/admin/admindocs`.
  122. Tags
  123. ====
  124. Tags look like this: ``{% tag %}``. Tags are more complex than variables: Some
  125. create text in the output, some control flow by performing loops or logic, and
  126. some load external information into the template to be used by later variables.
  127. Some tags require beginning and ending tags (i.e. ``{% tag %} ... tag contents
  128. ... {% endtag %}``).
  129. Django ships with about two dozen built-in template tags. You can read all about
  130. them in the :ref:`built-in tag reference <ref-templates-builtins-tags>`. To give
  131. you a taste of what's available, here are some of the more commonly used
  132. tags:
  133. :ttag:`for`
  134. Loop over each item in an array. For example, to display a list of athletes
  135. provided in ``athlete_list``::
  136. <ul>
  137. {% for athlete in athlete_list %}
  138. <li>{{ athlete.name }}</li>
  139. {% endfor %}
  140. </ul>
  141. :ttag:`if` and ``else``
  142. Evaluates a variable, and if that variable is "true" the contents of the
  143. block are displayed::
  144. {% if athlete_list %}
  145. Number of athletes: {{ athlete_list|length }}
  146. {% else %}
  147. No athletes.
  148. {% endif %}
  149. In the above, if ``athlete_list`` is not empty, the number of athletes
  150. will be displayed by the ``{{ athlete_list|length }}`` variable.
  151. You can also use filters and various operators in the ``if`` tag::
  152. {% if athlete_list|length > 1 %}
  153. Team: {% for athlete in athlete_list %} ... {% endfor %}
  154. {% else %}
  155. Athlete: {{ athlete_list.0.name }}
  156. {% endif %}
  157. :ttag:`block` and :ttag:`extends`
  158. Set up `template inheritance`_ (see below), a powerful way
  159. of cutting down on "boilerplate" in templates.
  160. Again, the above is only a selection of the whole list; see the :ref:`built-in
  161. tag reference <ref-templates-builtins-tags>` for the complete list.
  162. You can also create your own custom template tags; see
  163. :doc:`/howto/custom-template-tags`.
  164. .. seealso::
  165. Django's admin interface can include a complete reference of all template
  166. tags and filters available for a given site. See
  167. :doc:`/ref/contrib/admin/admindocs`.
  168. Comments
  169. ========
  170. To comment-out part of a line in a template, use the comment syntax: ``{# #}``.
  171. For example, this template would render as ``'hello'``::
  172. {# greeting #}hello
  173. A comment can contain any template code, invalid or not. For example::
  174. {# {% if foo %}bar{% else %} #}
  175. This syntax can only be used for single-line comments (no newlines are permitted
  176. between the ``{#`` and ``#}`` delimiters). If you need to comment out a
  177. multiline portion of the template, see the :ttag:`comment` tag.
  178. .. _template-inheritance:
  179. Template inheritance
  180. ====================
  181. The most powerful -- and thus the most complex -- part of Django's template
  182. engine is template inheritance. Template inheritance allows you to build a base
  183. "skeleton" template that contains all the common elements of your site and
  184. defines **blocks** that child templates can override.
  185. It's easiest to understand template inheritance by starting with an example::
  186. <!DOCTYPE html>
  187. <html lang="en">
  188. <head>
  189. <link rel="stylesheet" href="style.css" />
  190. <title>{% block title %}My amazing site{% endblock %}</title>
  191. </head>
  192. <body>
  193. <div id="sidebar">
  194. {% block sidebar %}
  195. <ul>
  196. <li><a href="/">Home</a></li>
  197. <li><a href="/blog/">Blog</a></li>
  198. </ul>
  199. {% endblock %}
  200. </div>
  201. <div id="content">
  202. {% block content %}{% endblock %}
  203. </div>
  204. </body>
  205. </html>
  206. This template, which we'll call ``base.html``, defines a simple HTML skeleton
  207. document that you might use for a simple two-column page. It's the job of
  208. "child" templates to fill the empty blocks with content.
  209. In this example, the ``{% block %}`` tag defines three blocks that child
  210. templates can fill in. All the ``block`` tag does is to tell the template
  211. engine that a child template may override those portions of the template.
  212. A child template might look like this::
  213. {% extends "base.html" %}
  214. {% block title %}My amazing blog{% endblock %}
  215. {% block content %}
  216. {% for entry in blog_entries %}
  217. <h2>{{ entry.title }}</h2>
  218. <p>{{ entry.body }}</p>
  219. {% endfor %}
  220. {% endblock %}
  221. The ``{% extends %}`` tag is the key here. It tells the template engine that
  222. this template "extends" another template. When the template system evaluates
  223. this template, first it locates the parent -- in this case, "base.html".
  224. At that point, the template engine will notice the three ``{% block %}`` tags
  225. in ``base.html`` and replace those blocks with the contents of the child
  226. template. Depending on the value of ``blog_entries``, the output might look
  227. like::
  228. <!DOCTYPE html>
  229. <html lang="en">
  230. <head>
  231. <link rel="stylesheet" href="style.css" />
  232. <title>My amazing blog</title>
  233. </head>
  234. <body>
  235. <div id="sidebar">
  236. <ul>
  237. <li><a href="/">Home</a></li>
  238. <li><a href="/blog/">Blog</a></li>
  239. </ul>
  240. </div>
  241. <div id="content">
  242. <h2>Entry one</h2>
  243. <p>This is my first entry.</p>
  244. <h2>Entry two</h2>
  245. <p>This is my second entry.</p>
  246. </div>
  247. </body>
  248. </html>
  249. Note that since the child template didn't define the ``sidebar`` block, the
  250. value from the parent template is used instead. Content within a ``{% block %}``
  251. tag in a parent template is always used as a fallback.
  252. You can use as many levels of inheritance as needed. One common way of using
  253. inheritance is the following three-level approach:
  254. * Create a ``base.html`` template that holds the main look-and-feel of your
  255. site.
  256. * Create a ``base_SECTIONNAME.html`` template for each "section" of your
  257. site. For example, ``base_news.html``, ``base_sports.html``. These
  258. templates all extend ``base.html`` and include section-specific
  259. styles/design.
  260. * Create individual templates for each type of page, such as a news
  261. article or blog entry. These templates extend the appropriate section
  262. template.
  263. This approach maximizes code reuse and makes it easy to add items to shared
  264. content areas, such as section-wide navigation.
  265. Here are some tips for working with inheritance:
  266. * If you use ``{% extends %}`` in a template, it must be the first template
  267. tag in that template. Template inheritance won't work, otherwise.
  268. * More ``{% block %}`` tags in your base templates are better. Remember,
  269. child templates don't have to define all parent blocks, so you can fill
  270. in reasonable defaults in a number of blocks, then only define the ones
  271. you need later. It's better to have more hooks than fewer hooks.
  272. * If you find yourself duplicating content in a number of templates, it
  273. probably means you should move that content to a ``{% block %}`` in a
  274. parent template.
  275. * If you need to get the content of the block from the parent template,
  276. the ``{{ block.super }}`` variable will do the trick. This is useful
  277. if you want to add to the contents of a parent block instead of
  278. completely overriding it. Data inserted using ``{{ block.super }}`` will
  279. not be automatically escaped (see the `next section`_), since it was
  280. already escaped, if necessary, in the parent template.
  281. * For extra readability, you can optionally give a *name* to your
  282. ``{% endblock %}`` tag. For example::
  283. {% block content %}
  284. ...
  285. {% endblock content %}
  286. In larger templates, this technique helps you see which ``{% block %}``
  287. tags are being closed.
  288. Finally, note that you can't define multiple ``{% block %}`` tags with the same
  289. name in the same template. This limitation exists because a block tag works in
  290. "both" directions. That is, a block tag doesn't just provide a hole to fill --
  291. it also defines the content that fills the hole in the *parent*. If there were
  292. two similarly-named ``{% block %}`` tags in a template, that template's parent
  293. wouldn't know which one of the blocks' content to use.
  294. .. _next section: #automatic-html-escaping
  295. .. _automatic-html-escaping:
  296. Automatic HTML escaping
  297. =======================
  298. When generating HTML from templates, there's always a risk that a variable will
  299. include characters that affect the resulting HTML. For example, consider this
  300. template fragment::
  301. Hello, {{ name }}.
  302. At first, this seems like a harmless way to display a user's name, but consider
  303. what would happen if the user entered his name as this::
  304. <script>alert('hello')</script>
  305. With this name value, the template would be rendered as::
  306. Hello, <script>alert('hello')</script>
  307. ...which means the browser would pop-up a JavaScript alert box!
  308. Similarly, what if the name contained a ``'<'`` symbol, like this?
  309. <b>username
  310. That would result in a rendered template like this::
  311. Hello, <b>username
  312. ...which, in turn, would result in the remainder of the Web page being bolded!
  313. Clearly, user-submitted data shouldn't be trusted blindly and inserted directly
  314. into your Web pages, because a malicious user could use this kind of hole to
  315. do potentially bad things. This type of security exploit is called a
  316. `Cross Site Scripting`_ (XSS) attack.
  317. To avoid this problem, you have two options:
  318. * One, you can make sure to run each untrusted variable through the
  319. ``escape`` filter (documented below), which converts potentially harmful
  320. HTML characters to unharmful ones. This was the default solution
  321. in Django for its first few years, but the problem is that it puts the
  322. onus on *you*, the developer / template author, to ensure you're escaping
  323. everything. It's easy to forget to escape data.
  324. * Two, you can take advantage of Django's automatic HTML escaping. The
  325. remainder of this section describes how auto-escaping works.
  326. By default in Django, every template automatically escapes the output
  327. of every variable tag. Specifically, these five characters are
  328. escaped:
  329. * ``<`` is converted to ``&lt;``
  330. * ``>`` is converted to ``&gt;``
  331. * ``'`` (single quote) is converted to ``&#39;``
  332. * ``"`` (double quote) is converted to ``&quot;``
  333. * ``&`` is converted to ``&amp;``
  334. Again, we stress that this behavior is on by default. If you're using Django's
  335. template system, you're protected.
  336. .. _Cross Site Scripting: http://en.wikipedia.org/wiki/Cross-site_scripting
  337. How to turn it off
  338. ------------------
  339. If you don't want data to be auto-escaped, on a per-site, per-template level or
  340. per-variable level, you can turn it off in several ways.
  341. Why would you want to turn it off? Because sometimes, template variables
  342. contain data that you *intend* to be rendered as raw HTML, in which case you
  343. don't want their contents to be escaped. For example, you might store a blob of
  344. HTML in your database and want to embed that directly into your template. Or,
  345. you might be using Django's template system to produce text that is *not* HTML
  346. -- like an email message, for instance.
  347. For individual variables
  348. ~~~~~~~~~~~~~~~~~~~~~~~~
  349. To disable auto-escaping for an individual variable, use the ``safe`` filter::
  350. This will be escaped: {{ data }}
  351. This will not be escaped: {{ data|safe }}
  352. Think of *safe* as shorthand for *safe from further escaping* or *can be
  353. safely interpreted as HTML*. In this example, if ``data`` contains ``'<b>'``,
  354. the output will be::
  355. This will be escaped: &lt;b&gt;
  356. This will not be escaped: <b>
  357. For template blocks
  358. ~~~~~~~~~~~~~~~~~~~
  359. To control auto-escaping for a template, wrap the template (or just a
  360. particular section of the template) in the ``autoescape`` tag, like so::
  361. {% autoescape off %}
  362. Hello {{ name }}
  363. {% endautoescape %}
  364. The ``autoescape`` tag takes either ``on`` or ``off`` as its argument. At
  365. times, you might want to force auto-escaping when it would otherwise be
  366. disabled. Here is an example template::
  367. Auto-escaping is on by default. Hello {{ name }}
  368. {% autoescape off %}
  369. This will not be auto-escaped: {{ data }}.
  370. Nor this: {{ other_data }}
  371. {% autoescape on %}
  372. Auto-escaping applies again: {{ name }}
  373. {% endautoescape %}
  374. {% endautoescape %}
  375. The auto-escaping tag passes its effect onto templates that extend the
  376. current one as well as templates included via the ``include`` tag, just like
  377. all block tags. For example::
  378. # base.html
  379. {% autoescape off %}
  380. <h1>{% block title %}{% endblock %}</h1>
  381. {% block content %}
  382. {% endblock %}
  383. {% endautoescape %}
  384. # child.html
  385. {% extends "base.html" %}
  386. {% block title %}This & that{% endblock %}
  387. {% block content %}{{ greeting }}{% endblock %}
  388. Because auto-escaping is turned off in the base template, it will also be
  389. turned off in the child template, resulting in the following rendered
  390. HTML when the ``greeting`` variable contains the string ``<b>Hello!</b>``::
  391. <h1>This & that</h1>
  392. <b>Hello!</b>
  393. Notes
  394. -----
  395. Generally, template authors don't need to worry about auto-escaping very much.
  396. Developers on the Python side (people writing views and custom filters) need to
  397. think about the cases in which data shouldn't be escaped, and mark data
  398. appropriately, so things Just Work in the template.
  399. If you're creating a template that might be used in situations where you're
  400. not sure whether auto-escaping is enabled, then add an ``escape`` filter to any
  401. variable that needs escaping. When auto-escaping is on, there's no danger of
  402. the ``escape`` filter *double-escaping* data -- the ``escape`` filter does not
  403. affect auto-escaped variables.
  404. String literals and automatic escaping
  405. --------------------------------------
  406. As we mentioned earlier, filter arguments can be strings::
  407. {{ data|default:"This is a string literal." }}
  408. All string literals are inserted **without** any automatic escaping into the
  409. template -- they act as if they were all passed through the ``safe`` filter.
  410. The reasoning behind this is that the template author is in control of what
  411. goes into the string literal, so they can make sure the text is correctly
  412. escaped when the template is written.
  413. This means you would write ::
  414. {{ data|default:"3 &lt; 2" }}
  415. ...rather than ::
  416. {{ data|default:"3 < 2" }} <-- Bad! Don't do this.
  417. This doesn't affect what happens to data coming from the variable itself.
  418. The variable's contents are still automatically escaped, if necessary, because
  419. they're beyond the control of the template author.
  420. .. _template-accessing-methods:
  421. Accessing method calls
  422. ======================
  423. Most method calls attached to objects are also available from within templates.
  424. This means that templates have access to much more than just class attributes
  425. (like field names) and variables passed in from views. For example, the Django
  426. ORM provides the :ref:`"entry_set"<topics-db-queries-related>` syntax for
  427. finding a collection of objects related on a foreign key. Therefore, given
  428. a model called "comment" with a foreign key relationship to a model called
  429. "task" you can loop through all comments attached to a given task like this::
  430. {% for comment in task.comment_set.all %}
  431. {{ comment }}
  432. {% endfor %}
  433. Similarly, :doc:`QuerySets</ref/models/querysets>` provide a ``count()`` method
  434. to count the number of objects they contain. Therefore, you can obtain a count
  435. of all comments related to the current task with::
  436. {{ task.comment_set.all.count }}
  437. And of course you can easily access methods you've explicitly defined on your
  438. own models::
  439. # In model
  440. class Task(models.Model):
  441. def foo(self):
  442. return "bar"
  443. # In template
  444. {{ task.foo }}
  445. Because Django intentionally limits the amount of logic processing available
  446. in the template language, it is not possible to pass arguments to method calls
  447. accessed from within templates. Data should be calculated in views, then passed
  448. to templates for display.
  449. .. _loading-custom-template-libraries:
  450. Custom tag and filter libraries
  451. ===============================
  452. Certain applications provide custom tag and filter libraries. To access them in
  453. a template, use the ``{% load %}`` tag::
  454. {% load comments %}
  455. {% comment_form for blogs.entries entry.id with is_public yes %}
  456. In the above, the ``load`` tag loads the ``comments`` tag library, which then
  457. makes the ``comment_form`` tag available for use. Consult the documentation
  458. area in your admin to find the list of custom libraries in your installation.
  459. The ``{% load %}`` tag can take multiple library names, separated by spaces.
  460. Example::
  461. {% load comments i18n %}
  462. See :doc:`/howto/custom-template-tags` for information on writing your own custom
  463. template libraries.
  464. Custom libraries and template inheritance
  465. -----------------------------------------
  466. When you load a custom tag or filter library, the tags/filters are only made
  467. available to the current template -- not any parent or child templates along
  468. the template-inheritance path.
  469. For example, if a template ``foo.html`` has ``{% load comments %}``, a child
  470. template (e.g., one that has ``{% extends "foo.html" %}``) will *not* have
  471. access to the comments template tags and filters. The child template is
  472. responsible for its own ``{% load comments %}``.
  473. This is a feature for the sake of maintainability and sanity.