# Getting ZgotmplZ by printing spaces inside a simple custom shortcode

**URL:** <https://discourse.gohugo.io/t/getting-zgotmplz-by-printing-spaces-inside-a-simple-custom-shortcode/47722>\
**Category:** support\
**Tags:** shortcodes\
**Created:** [January 6, 2024, 5:55am UTC](https://discourse.gohugo.io/t/getting-zgotmplz-by-printing-spaces-inside-a-simple-custom-shortcode/47722 "2024-01-06T05:55:38Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![mgouin](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/mgouin/32/20961_2.png) [@mgouin](https://discourse.gohugo.io/u/mgouin)\
**Post date:** [January 6, 2024, 5:55am UTC](https://discourse.gohugo.io/t/getting-zgotmplz-by-printing-spaces-inside-a-simple-custom-shortcode/47722/1 "2024-01-06T05:55:38Z")

</div>

Hello,

Long story, but I was trying to use the print fucntion to manually insert spaces in template to align stuff. I was getting the strange ZgotmplZ string. I was able to create a very simple example to re-create the problem.

I’m using hugo:

```auto
hugo v0.121.1-00b46fed8e47f7bb0a85d7cfc2d9f1356379b740+extended linux/amd64 BuildDate=2023-12-08T08:47:45Z VendorInfo=gohugoio
GOOS="linux"
GOARCH="amd64"
GOVERSION="go1.21.5"
github.com/sass/libsass="3.6.5"
github.com/webmproject/libwebp="v1.3.2"

```

The example does not make a lot of sense, but it is just to keep it super simple.

generate\_error.html shortcode:

```html
<!-- OK -->
<img src="a.png" {{ print "x" }} >

<!-- Error -->
<img src="a.png" {{ print " " }} >

```

test\_post.md:

```auto
## Testing

Before shortcode

{{< generate_error input_parameter >}}

After shortcode

```

Html output source:

```html
<p>Before shortcode</p>

<img src="a.png" x >

<img src="a.png" ZgotmplZ >

<p>After shortcode</p>

```

Is this normal? Thanks!  
Mathieu

---

<div class="post-metadata">

**Author:** ![panchtatvam](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/panchtatvam/32/20935_2.png) [@panchtatvam](https://discourse.gohugo.io/u/panchtatvam)\
**Post date:** [January 6, 2024, 9:20am UTC](https://discourse.gohugo.io/t/getting-zgotmplz-by-printing-spaces-inside-a-simple-custom-shortcode/47722/2 "2024-01-06T09:20:42Z")

</div>

This is [unsafe HTML](https://stackoverflow.com/questions/14765395/why-am-i-seeing-zgotmplz-in-my-go-html-template-output).

You may use `safe.HTML` provided by Hugo use the following :

```auto
<img src="a.png" {{ print " " | safeHTML }} >

```

To allow unsafe HTML for all, you may set [Goldmark config](https://gohugo.io/getting-started/configuration-markup/#goldmark) in your configuration file as ( however unsafe HTML is not good ) :

```auto
[markup]
  [markup.goldmark]
    [markup.goldmark.renderer]
      unsafe = true

```

---

<div class="post-metadata">

**Author:** ![chrillek](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/chrillek/32/19797_2.png) [@chrillek](https://discourse.gohugo.io/u/chrillek)\
**Post date:** [January 6, 2024, 9:26am UTC](https://discourse.gohugo.io/t/getting-zgotmplz-by-printing-spaces-inside-a-simple-custom-shortcode/47722/3 "2024-01-06T09:26:13Z")

</div>

> [@panchtatvam](#):
>
> however unsafe HTML is not good

If you have full control over the MD sources, unsafe HTML is ok. Why wouldn’t it be?

---

<div class="post-metadata">

**Author:** ![panchtatvam](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/panchtatvam/32/20935_2.png) [@panchtatvam](https://discourse.gohugo.io/u/panchtatvam)\
**Post date:** [January 6, 2024, 9:28am UTC](https://discourse.gohugo.io/t/getting-zgotmplz-by-printing-spaces-inside-a-simple-custom-shortcode/47722/4 "2024-01-06T09:28:26Z")

</div>

> [@chrillek](#):
>
> If you have full control over the MD sources

Then it may be the case.

I personally only allow HTML specifically so I don’t break something by unsanitized HTML.

---

<div class="post-metadata">

**Author:** ![jmooring](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/jmooring/32/4214_2.png) [@jmooring](https://discourse.gohugo.io/u/jmooring)\
**Post date:** [January 6, 2024, 12:53pm UTC](https://discourse.gohugo.io/t/getting-zgotmplz-by-printing-spaces-inside-a-simple-custom-shortcode/47722/5 "2024-01-06T12:53:42Z")

</div>

To clarify…

1) Your HTML is _not_ unsafe. Your are seeing the effects of Go’s [html/template](https://pkg.go.dev/html/template) package as it sanitizes the rendered HTML to make it safe against code injection.

2) The `markup.goldmark.renderer.unsafe` configuration parameter is not relevant to this topic. When set to `false` (the default), the markdown renderer ([Goldmark](https://github.com/yuin/goldmark)) replaces HTML within the markdown with:

`<!-- raw HTML omitted -->`

Clearly that is not a factor—you are not mixing HTML within your markdown.

3) The [`safeHTML`](https://gohugo.io/functions/safe/html/) template function is not relevant to this topic. That function declares an HTML element (and its descendants) as safe, and Go’s html/template package will not perform any santization.

4) The fix…

When parsing the template, Go’s html/template package treats your `printf` insertion as an HTML attribute, so you have to declare the attribute as safe with the [`safeHTMLAttr`](https://gohugo.io/functions/safe/htmlattr/) template function:

```plaintext
<img src="a.png" {{ print " " | safeHTMLAttr }}>

```

5) Why doesn’t this happen with `<img src="a.png" {{ print "x" }}>` ?

That’s a question for the Go maintainers, but I suspect that `"x"` is seen as a boolean HTML attribute without an attribute value (like the global `hidden` attribute), and is treated as safe.

All of the examples below are treated as unsafe:

```auto
<img src="a.png" {{ print " " }}>
<img src="a.png" {{ print "x " }}>
<img src="a.png" {{ print " x" }}>
<img src="a.png" {{ print " x " }}>
<img src="a.png" {{ print "x y" }}>

```

---

<div class="post-metadata">

**Author:** ![mgouin](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/mgouin/32/20961_2.png) [@mgouin](https://discourse.gohugo.io/u/mgouin)\
**Post date:** [January 6, 2024, 5:10pm UTC](https://discourse.gohugo.io/t/getting-zgotmplz-by-printing-spaces-inside-a-simple-custom-shortcode/47722/6 "2024-01-06T17:10:51Z")

</div>

Thanks a lot @jmooring for your detailed and complete answer. It solved my spacing issue perfectly.

Do you mind providing guidance on how to properly deal with html output spacing formatting? I already know about the `{{- xxx -}}`, `{{- xxx }}` and `{{ xxx -}}`. Maybe I’m just too OCD about the html output 🙂

Thanks again!

---

<div class="post-metadata">

**Author:** ![jmooring](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/jmooring/32/4214_2.png) [@jmooring](https://discourse.gohugo.io/u/jmooring)\
**Post date:** [January 6, 2024, 5:21pm UTC](https://discourse.gohugo.io/t/getting-zgotmplz-by-printing-spaces-inside-a-simple-custom-shortcode/47722/7 "2024-01-06T17:21:39Z")

</div>

> [@mgouin](#):
>
> how to properly deal with html output spacing formatting

Not sure what that means. Can you provide an example of input vs. desired output?

> [@mgouin](#):
>
> Maybe I’m just too OCD about the html output

Yeah, probably. In production you will minify, and in development you will typically use the brower’s dev tools (which formats for you) to inspect. The only time I look at the source (Ctrl+U in the browser) is when I suspect that the browser’s dev tools have attempted to correct invalid HTML (which is kind of annoying, though I understand the intent—match what’s rendered in the browser).

---

<div class="post-metadata">

**Author:** ![mgouin](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/mgouin/32/20961_2.png) [@mgouin](https://discourse.gohugo.io/u/mgouin)\
**Post date:** [January 7, 2024, 9:02pm UTC](https://discourse.gohugo.io/t/getting-zgotmplz-by-printing-spaces-inside-a-simple-custom-shortcode/47722/8 "2024-01-07T21:02:47Z")

</div>

Ok, thanks. Yes, I completely forgot about minify. It’s just that during development I wanted to have better control over my indentation. And yes, I use Ctrl + U a lot 🙂

---

<div class="post-metadata">

**Author:** ![system](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/system/32/1_2.png) [@system](https://discourse.gohugo.io/u/system)\
**Post date:** [January 9, 2024, 9:03pm UTC](https://discourse.gohugo.io/t/getting-zgotmplz-by-printing-spaces-inside-a-simple-custom-shortcode/47722/9 "2024-01-09T21:03:17Z")

</div>

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.
