* Use Jinja2 escape functionality to escape html attributes in value response * Add tests * fix formatting