a5e08f7bcc
I installed the rails_xss plugin, for the main purpose of seeing what will break with Rails 3.0 (where the behaviour of the plugin is the default). I think I've fixed everything, but let me know if you see stuff that is HTML-escaped, which shouldn't be. As a side benefit, we now use Erubis, rather than ERB, to render templates. They tell me it's faster ...
14 lines
206 B
HTML
14 lines
206 B
HTML
<?xml version="1.0" ?>
|
|
<?rb
|
|
lang = 'en'
|
|
list = ['<aaa>', 'b&b', '"ccc"']
|
|
?>
|
|
<html lang="@!{lang}@">
|
|
<body>
|
|
<ul>
|
|
<?rb for item in list ?>
|
|
<li>@{item}@</li>
|
|
<?rb end ?>
|
|
</ul>
|
|
</body>
|
|
</html>
|