Rails_xss Plugin

I installed the rails_xss plugin, for
the main purpose of seeing what will
break with Rails 3.0 (where the behaviour
of the plugin is the default). I think
I've fixed everything, but let me know if you
see stuff that is HTML-escaped, which
shouldn't be.

As a side benefit, we now use Erubis,
rather than ERB, to render templates.
They tell me it's faster ...
This commit is contained in:
Jacques Distler 2010-05-26 00:27:49 -05:00
parent d6be09e0f0
commit a5e08f7bcc
343 changed files with 43874 additions and 37 deletions

View file

@ -0,0 +1,26 @@
<%
(let ((user "Erubis")
(items '("<aaa>" "b&b" "\"ccc\""))
(i 0))
%>
<p>Hello <%= user %>!</p>
<table>
<tbody>
<%
(for-each
(lambda (item)
(set! i (+ i 1))
%>
<tr bgcolor="<%= (if (= (modulo i 2) 0) "#FFCCCC" "#CCCCFF") %>">
<td><%= i %></td>
<td><%= item %></td>
</tr>
<%
) ; lambda end
items) ; for-each end
%>
</tbody>
</table>
<%
) ; let end
%>