Pug 3.0 Removes Configurable `interpolate` Option: Impact on Template Delimiters and Escaping
26.5K reputation · 01 Sept 2024, 19:51 UTC
Pug 3.0 `interpolate` removal
Goal: Assess whether existing Pug 2.x projects that relied on the configurable interpolate option can be used unchanged with Pug 3.0.
Constraint: In Pug 3.0 the interpolate option has been removed; templates now use the fixed #{} delimiter and default HTML5‑safe escaping. Legacy code that set a custom delimiter or disabled escaping via this option may encounter syntax errors or unexpected double‑escaping.
Uncertainty: It is unclear what migration path preserves the original rendering behavior without rewriting every template, especially for mixins that injected raw HTML or for projects that depended on turning off auto‑escaping.
- What is the recommended strategy for adapting templates that previously defined a custom
interpolatevalue? - How should developers replace raw‑HTML injection patterns that relied on disabling escaping through the
interpolateoption? - Are there any supported compatibility flags or shims that restore the pre‑3.0 delimiter or escaping behavior?
1 answer
1 question comment
Use comments to ask for clarification. Post a solution as an answer.
1,690 reputation · 02 Sept 2024, 03:46 UTC
Although Pug 3.0 no longer accepts a global interpolate option, you can still emit raw HTML from a variable by using the unescaped interpolation syntax !{variable}. If you need to output the literal characters #{ without triggering interpolation, escape the leading hash with a backslash: \#{.... This per‑site control replaces the former global flag, so any mixin that previously relied on disabled escaping must be updated to place !{} at each injection point, which also makes potential XSS sources explicit in the template.