JinjaString class

A string wrapper that tracks the origin of its parts (user input vs template).

This mechanics is the core of Dinja's security model. It distinguishes between trusted template text and untrusted user input, allowing for automatic escaping of the latter to prevent injection attacks.

Annotations
  • @immutable

Constructors

JinjaString(List<JinjaStringPart> parts, {bool isSafe = false})
const
JinjaString.from(String val, {bool isInput = false, bool isSafe = false})
factory
JinjaString.template(String val)
Creates a JinjaString from a raw string, marking it as template (not input).
factory
JinjaString.user(String val)
Creates a JinjaString from a raw string, marking it as user input.
factory

Properties

allPartsAreInput → bool
Returns true if ALL parts of this string are marked as user input.
no setter
hashCode → int
The hash code for this object.
no setteroverride
isSafe → bool
Whether this string is considered "safe" (not needing further escaping).
final
length → int
The length of the full string.
no setter
parts → List<JinjaStringPart>
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited

Methods

escape() → JinjaString
Returns a new JinjaString with special characters escaped.
markInput() → JinjaString
Helper to create a new JinjaString where all parts are marked as input.
markInputBasedOn(JinjaString other) → JinjaString
Mark this string as input if other has ALL parts as input. This is used for operations like split where the resulting parts should inherit the "taint" of the original string if the original was fully tainted.
markSafe() → JinjaString
Helper to create a new JinjaString marked as safe.
noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
substring(int start, [int? end]) → JinjaString
toLowerCase() → JinjaString
toString() → String
Returns the full string content, ignoring input markers.
override
toUpperCase() → JinjaString
trim() → JinjaString
trimLeft() → JinjaString
trimRight() → JinjaString

Operators

operator +(JinjaString other) → JinjaString
Concatenates this string with another.
operator ==(Object other) → bool
Compares content only, as Jinja2 and llama.cpp do: part boundaries, input markers and isSafe do not affect equality or hashCode.
override
operator [](int index) → JinjaString