Rails_xss Plugin
I installed the rails_xss plugin, for the main purpose of seeing what will break with Rails 3.0 (where the behaviour of the plugin is the default). I think I've fixed everything, but let me know if you see stuff that is HTML-escaped, which shouldn't be. As a side benefit, we now use Erubis, rather than ERB, to render templates. They tell me it's faster ...
This commit is contained in:
parent
d6be09e0f0
commit
a5e08f7bcc
343 changed files with 43874 additions and 37 deletions
14
vendor/plugins/erubis-2.6.5/test/data/users-guide/example10.xhtml
vendored
Normal file
14
vendor/plugins/erubis-2.6.5/test/data/users-guide/example10.xhtml
vendored
Normal file
|
@ -0,0 +1,14 @@
|
|||
<?xml version="1.0" ?>
|
||||
<?rb
|
||||
lang = 'en'
|
||||
list = ['<aaa>', 'b&b', '"ccc"']
|
||||
?>
|
||||
<html lang="@!{lang}@">
|
||||
<body>
|
||||
<ul>
|
||||
<?rb for item in list ?>
|
||||
<li>@{item}@</li>
|
||||
<?rb end ?>
|
||||
</ul>
|
||||
</body>
|
||||
</html>
|
Loading…
Add table
Add a link
Reference in a new issue