Rails_xss Plugin
I installed the rails_xss plugin, for the main purpose of seeing what will break with Rails 3.0 (where the behaviour of the plugin is the default). I think I've fixed everything, but let me know if you see stuff that is HTML-escaped, which shouldn't be. As a side benefit, we now use Erubis, rather than ERB, to render templates. They tell me it's faster ...
This commit is contained in:
parent
d6be09e0f0
commit
a5e08f7bcc
343 changed files with 43874 additions and 37 deletions
26
vendor/plugins/erubis-2.6.5/examples/basic/example.escheme
vendored
Normal file
26
vendor/plugins/erubis-2.6.5/examples/basic/example.escheme
vendored
Normal file
|
@ -0,0 +1,26 @@
|
|||
<%
|
||||
(let ((user "Erubis")
|
||||
(items '("<aaa>" "b&b" "\"ccc\""))
|
||||
(i 0))
|
||||
%>
|
||||
<p>Hello <%= user %>!</p>
|
||||
<table>
|
||||
<tbody>
|
||||
<%
|
||||
(for-each
|
||||
(lambda (item)
|
||||
(set! i (+ i 1))
|
||||
%>
|
||||
<tr bgcolor="<%= (if (= (modulo i 2) 0) "#FFCCCC" "#CCCCFF") %>">
|
||||
<td><%= i %></td>
|
||||
<td><%= item %></td>
|
||||
</tr>
|
||||
<%
|
||||
) ; lambda end
|
||||
items) ; for-each end
|
||||
%>
|
||||
</tbody>
|
||||
</table>
|
||||
<%
|
||||
) ; let end
|
||||
%>
|
Loading…
Add table
Add a link
Reference in a new issue