a5e08f7bcc
I installed the rails_xss plugin, for the main purpose of seeing what will break with Rails 3.0 (where the behaviour of the plugin is the default). I think I've fixed everything, but let me know if you see stuff that is HTML-escaped, which shouldn't be. As a side benefit, we now use Erubis, rather than ERB, to render templates. They tell me it's faster ...
28 lines
373 B
Plaintext
28 lines
373 B
Plaintext
$ ruby example2.rb
|
|
----- script source ---
|
|
_buf = ''; _buf << '<ul>
|
|
'; _buf << ' '; for item in list ; _buf << '
|
|
'; _buf << ' <li>
|
|
'; _buf << ( item ).to_s; _buf << '
|
|
'; _buf << ' </li>
|
|
'; _buf << ' '; end ; _buf << '
|
|
'; _buf << '</ul>
|
|
';
|
|
_buf.to_s
|
|
----- result ----------
|
|
<ul>
|
|
|
|
<li>
|
|
aaa
|
|
</li>
|
|
|
|
<li>
|
|
bbb
|
|
</li>
|
|
|
|
<li>
|
|
ccc
|
|
</li>
|
|
|
|
</ul>
|