a5e08f7bcc
I installed the rails_xss plugin, for the main purpose of seeing what will break with Rails 3.0 (where the behaviour of the plugin is the default). I think I've fixed everything, but let me know if you see stuff that is HTML-escaped, which shouldn't be. As a side benefit, we now use Erubis, rather than ERB, to render templates. They tell me it's faster ...
23 lines
464 B
Plaintext
23 lines
464 B
Plaintext
$ ruby example3.rb 2> stderr.log
|
|
----- script source ---
|
|
_buf = ''; for item in list
|
|
_buf << ' <p>'; _buf << Erubis::XmlHelper.escape_xml( item ); _buf << '</p>
|
|
<p>'; _buf << ( item ).to_s; _buf << '</p>
|
|
<p>'; $stderr.puts("*** debug: item=#{(item).inspect}"); _buf << '</p>
|
|
|
|
'; end
|
|
_buf.to_s
|
|
----- result ----------
|
|
<p><aaa></p>
|
|
<p><aaa></p>
|
|
<p></p>
|
|
|
|
<p>b&b</p>
|
|
<p>b&b</p>
|
|
<p></p>
|
|
|
|
<p>"ccc"</p>
|
|
<p>"ccc"</p>
|
|
<p></p>
|
|
|