a5e08f7bcc
I installed the rails_xss plugin, for the main purpose of seeing what will break with Rails 3.0 (where the behaviour of the plugin is the default). I think I've fixed everything, but let me know if you see stuff that is HTML-escaped, which shouldn't be. As a side benefit, we now use Erubis, rather than ERB, to render templates. They tell me it's faster ...
18 lines
349 B
XML
18 lines
349 B
XML
$ ruby example10.rb
|
|
_buf = ''; _buf << '<?xml version="1.0" ?>
|
|
';
|
|
lang = 'en'
|
|
list = ['<aaa>', 'b&b', '"ccc"']
|
|
|
|
_buf << '<html lang="'; _buf << (lang).to_s; _buf << '">
|
|
<body>
|
|
<ul>
|
|
'; for item in list
|
|
_buf << ' <li>'; _buf << Erubis::XmlHelper.escape_xml(item); _buf << '</li>
|
|
'; end
|
|
_buf << ' </ul>
|
|
</body>
|
|
</html>
|
|
';
|
|
_buf.to_s
|