instiki/vendor/plugins/erubis-2.6.5/examples/basic/example.ec
Jacques Distler a5e08f7bcc Rails_xss Plugin
I installed the rails_xss plugin, for
the main purpose of seeing what will
break with Rails 3.0 (where the behaviour
of the plugin is the default). I think
I've fixed everything, but let me know if you
see stuff that is HTML-escaped, which
shouldn't be.

As a side benefit, we now use Erubis,
rather than ERB, to render templates.
They tell me it's faster ...
2010-05-26 00:27:49 -05:00

43 lines
810 B
Plaintext

<%
#include <stdio.h>
void escape(char *str, FILE *out);
int main(int argc, char *argv[])
{
int i;
%>
<p>Hello <%== argv[0] %>!</p>
<table>
<tbody>
<% for (i = 1; i < argc; i++) { %>
<tr bgcolor="<%= i % 2 == 0 ? "#FFCCCC" : "#CCCCFF" %>">
<td><%= "%d", i %></td>
<td><%== argv[i] %></td>
</tr>
<% } %>
</tbody>
</table>
<%
return 0;
}
void escape(char *str, FILE *out)
{
char *pch;
for (pch = str; *pch != '\0'; pch++) {
switch (*pch) {
case '&': fputs("&amp;", out); break;
case '>': fputs("&gt;", out); break;
case '<': fputs("&lt;", out); break;
case '"': fputs("&quot;", out); break;
case '\'': fputs("&#039;", out); break;
default: fputc(*pch, out);
}
}
}
%>