a5e08f7bcc
I installed the rails_xss plugin, for the main purpose of seeing what will break with Rails 3.0 (where the behaviour of the plugin is the default). I think I've fixed everything, but let me know if you see stuff that is HTML-escaped, which shouldn't be. As a side benefit, we now use Erubis, rather than ERB, to render templates. They tell me it's faster ...
18 lines
348 B
Plaintext
18 lines
348 B
Plaintext
<?php
|
|
$user = "World";
|
|
$list = array('<aaa>', 'b&b', '"ccc"');
|
|
?>
|
|
<p>Hello @{$user}@!</p>
|
|
<table>
|
|
<tbody>
|
|
<?php $i = 0 ?>
|
|
<?php foreach ($list as $item) { ?>
|
|
<?php $i++; ?>
|
|
<tr bgcolor="@!{$i % 2 == 0 ? '#FFCCCC' : '#CCCCFF'}@">
|
|
<td>@!{$i}@</td>
|
|
<td>@{$item}@</td>
|
|
</tr>
|
|
<?php } ?>
|
|
</tbody>
|
|
</table>
|