Exercise 2: A Real, Legitimate SafeString Use Case — Possible Solution ==================================================================== THE FUNCTION ------------------------------ def render_bio_markdown(raw_text): # escape EVERYTHING first, THEN convert **bold** markers on the # now-safe text into real tags -- the only HTML this # function can ever produce is , never anything the raw # input itself tried to smuggle in escaped = html.escape(raw_text) with_bold = re.sub(r'\*\*(.+?)\*\*', r'\1', escaped) return SafeString(with_bold) VERIFIED, REAL RESULT ------------------------------ malicious_bio = "Loves **Python** and " result = render_bio_markdown(malicious_bio) print(result) # Loves Python and <script>alert(1)</script> Rendered through a real VarNode inside "

Bio: {{ bio }}

": render(bio=result) #

Bio: Loves Python and <script>alert(1)</script>

render(bio=malicious_bio) # the SAME raw text, not run through the function #

Bio: Loves **Python** and <script>alert(1)</script>

The **Python** marker only becomes a real tag when the text has genuinely been through render_bio_markdown() first; the identical raw text passed straight to the template shows the literal asterisks untouched, and the