View Helpers
hAttr()
Signature
Section titled “Signature”hAttr() — returns string
Available in: controller
Category: Sanitization Functions
Description
Section titled “Description”Encodes a value for safe use inside an HTML attribute. Use when building attribute values manually: <div title=“#hAttr(user.bio)#”>.
Parameters
Section titled “Parameters”| Name | Type | Required | Default | Description |
|---|---|---|---|---|
value | any | yes | — | The value to encode for HTML attribute context. |
Examples
Section titled “Examples”// 1. Safely encode a user-supplied string inside an HTML attribute
userBio = "Say ""hello"" & <wave>";
writeOutput('<div title="#hAttr(userBio)#">Hover me</div>');
<!--- Renders: <div title="Say "hello" & <wave>">Hover me</div> --->
// 2. Use directly in a view template to prevent XSS in attribute values
writeOutput('<input type="text" placeholder="#hAttr(params.search)#">');