a5e08f7bcc
I installed the rails_xss plugin, for the main purpose of seeing what will break with Rails 3.0 (where the behaviour of the plugin is the default). I think I've fixed everything, but let me know if you see stuff that is HTML-escaped, which shouldn't be. As a side benefit, we now use Erubis, rather than ERB, to render templates. They tell me it's faster ...
7 lines
100 B
Plaintext
7 lines
100 B
Plaintext
<% for item in list %>
|
|
<p><%= item %></p>
|
|
<p><%== item %></p>
|
|
<p><%=== item %></p>
|
|
|
|
<% end %>
|