a5e08f7bcc
I installed the rails_xss plugin, for the main purpose of seeing what will break with Rails 3.0 (where the behaviour of the plugin is the default). I think I've fixed everything, but let me know if you see stuff that is HTML-escaped, which shouldn't be. As a side benefit, we now use Erubis, rather than ERB, to render templates. They tell me it's faster ...
20 lines
434 B
XML
20 lines
434 B
XML
$ erubis -l php example.ephp
|
|
<<?php ?>?xml version="1.0"?>
|
|
<html>
|
|
<body>
|
|
<p>Hello <?php echo $user; ?>!</p>
|
|
<table>
|
|
<tbody>
|
|
<?php $i = 0; ?>
|
|
<?php foreach ($list as $item) { ?>
|
|
<?php $i++; ?>
|
|
<tr bgcolor="<?php echo $i % 2 == 0 ? '#FFCCCC' : '#CCCCFF'; ?>">
|
|
<td><?php echo $i; ?></td>
|
|
<td><?php echo htmlspecialchars($item); ?></td>
|
|
</tr>
|
|
<?php } ?>
|
|
</tbody>
|
|
</table>
|
|
</body>
|
|
</html>
|