# Dealing with escaped text from the api?

**URL:** <https://discuss.emberjs.com/t/dealing-with-escaped-text-from-the-api/8433>\
**Category:** Design\
**Created:** [July 22, 2015, 3:15pm UTC](https://discuss.emberjs.com/t/dealing-with-escaped-text-from-the-api/8433 "2015-07-22T15:15:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![robertoandred](https://avatars.discourse-cdn.com/v4/letter/r/b77776/32.png) [@robertoandred](https://discuss.emberjs.com/u/robertoandred)\
**Post date:** [July 22, 2015, 3:15pm UTC](https://discuss.emberjs.com/t/dealing-with-escaped-text-from-the-api/8433/1 "2015-07-22T15:15:34Z")

</div>

My api is escaping the unescaped user input I send it via ember-data. So when the data returned from the api is rendered, the text gets escaped twice resulting in html entities appearing in my text. What’s the proper way to handle this? Should the api not escape text and leave it up to Handlebars? Or is there a way to tell Ember that the text is already escaped?

---

<div class="post-metadata">

**Author:** ![broerse](https://sea1.discourse-cdn.com/flex019/user_avatar/discuss.emberjs.com/broerse/32/9497_2.png) [@broerse](https://discuss.emberjs.com/u/broerse)\
**Post date:** [July 22, 2015, 8:31pm UTC](https://discuss.emberjs.com/t/dealing-with-escaped-text-from-the-api/8433/2 "2015-07-22T20:31:37Z")

</div>

Helpers are replaced by components but I do this in a helper:

[https://github.com/broerse/ember-cli-blog/blob/master/app/helpers/format-markdown.js](https://github.com/broerse/ember-cli-blog/blob/master/app/helpers/format-markdown.js)

---

<div class="post-metadata">

**Author:** ![workmanw](https://sea1.discourse-cdn.com/flex019/user_avatar/discuss.emberjs.com/workmanw/32/14929_2.png) [@workmanw](https://discuss.emberjs.com/u/workmanw)\
**Post date:** [July 24, 2015, 5:19pm UTC](https://discuss.emberjs.com/t/dealing-with-escaped-text-from-the-api/8433/3 "2015-07-24T17:19:48Z")

</div>

IMHO The API should NOT escape text. It’s really the client’s job to ensure it doesn’t result in a XSS vulnerability. And it makes even less sense when you have alternate clients (mobile) consuming the API.

It’s not clear based your initial question if you were referring to WYSIWYG data or all text fields. If it’s the later, I would actually recommend you handle this at the ember-data level so that from the view/component/router/controller perspectives, the data is accurate (not-escaped).

The problem with escaped data is you often have to know explicitly it’s escaped/unescaped. You can’t always tell. So given that, I see one of two options. If ALL of your data is ALWAYS escaped, I would implement `normalizeHash` on the application serializer ([JSONSerializer - 4.6 - Ember API Documentation](http://emberjs.com/api/data/classes/DS.JSONSerializer.html#method_normalize)). If only some of your fields are escaped, I would implement a custom transform ([Transform - 4.6 - Ember API Documentation](http://emberjs.com/api/data/classes/DS.Transform.html)).
