Rails_xss Plugin
I installed the rails_xss plugin, for the main purpose of seeing what will break with Rails 3.0 (where the behaviour of the plugin is the default). I think I've fixed everything, but let me know if you see stuff that is HTML-escaped, which shouldn't be. As a side benefit, we now use Erubis, rather than ERB, to render templates. They tell me it's faster ...
This commit is contained in:
parent
d6be09e0f0
commit
a5e08f7bcc
343 changed files with 43874 additions and 37 deletions
45
vendor/plugins/erubis-2.6.5/examples/basic/example.ejava
vendored
Normal file
45
vendor/plugins/erubis-2.6.5/examples/basic/example.ejava
vendored
Normal file
|
@ -0,0 +1,45 @@
|
|||
<%
|
||||
import java.util.*;
|
||||
|
||||
public class example {
|
||||
|
||||
public static void main(String[] args) {
|
||||
String user = "Erubis";
|
||||
String[] list = { "<aaa>", "b&b", "\"ccc\"" };
|
||||
StringBuffer _buf = new StringBuffer();
|
||||
%>
|
||||
<p>Hello <%== user %>!</p>
|
||||
<table>
|
||||
<tbody>
|
||||
<% for (int i = 0; i < list.length; i++) { %>
|
||||
<tr bgcolor="<%= i % 2 == 0 ? "#FFCCCC" : "#CCCCFF" %>">
|
||||
<td><%= i + 1 %></td>
|
||||
<td><%== list[i] %></td>
|
||||
</tr>
|
||||
<% } %>
|
||||
</tbody>
|
||||
</table>
|
||||
<%
|
||||
System.out.print(_buf.toString());
|
||||
}
|
||||
|
||||
public static String escape(String s) {
|
||||
StringBuffer sb = new StringBuffer();
|
||||
for (int i = 0; i < s.length(); i++) {
|
||||
char ch = s.charAt(i);
|
||||
switch (ch) {
|
||||
case '<': sb.append("<"); break;
|
||||
case '>': sb.append(">"); break;
|
||||
case '&': sb.append("&"); break;
|
||||
case '"': sb.append("""); break;
|
||||
default: sb.append(ch);
|
||||
}
|
||||
}
|
||||
return sb.toString();
|
||||
}
|
||||
|
||||
public static String escape(int i) {
|
||||
return Integer.toString(i);
|
||||
}
|
||||
}
|
||||
%>
|
Loading…
Add table
Add a link
Reference in a new issue