a5e08f7bcc
I installed the rails_xss plugin, for the main purpose of seeing what will break with Rails 3.0 (where the behaviour of the plugin is the default). I think I've fixed everything, but let me know if you see stuff that is HTML-escaped, which shouldn't be. As a side benefit, we now use Erubis, rather than ERB, to render templates. They tell me it's faster ...
11 lines
336 B
Ruby
11 lines
336 B
Ruby
require 'erubis'
|
|
input = File.read('example3.eruby')
|
|
eruby = Erubis::EscapedEruby.new(input) # or Erubis::XmlEruby
|
|
|
|
puts "----- script source ---"
|
|
puts eruby.src # print script source
|
|
|
|
puts "----- result ----------"
|
|
list = ['<aaa>', 'b&b', '"ccc"']
|
|
puts eruby.result(binding()) # get result
|