a5e08f7bcc
I installed the rails_xss plugin, for the main purpose of seeing what will break with Rails 3.0 (where the behaviour of the plugin is the default). I think I've fixed everything, but let me know if you see stuff that is HTML-escaped, which shouldn't be. As a side benefit, we now use Erubis, rather than ERB, to render templates. They tell me it's faster ...
14 lines
240 B
Plaintext
14 lines
240 B
Plaintext
$ erubis -f context.rb example7.eruby
|
|
<h1>Users List</h1>
|
|
<ul>
|
|
<li>
|
|
<a href="mailto:foo@mail.com">foo</a>
|
|
</li>
|
|
<li>
|
|
<a href="mailto:bar@mail.net">bar</a>
|
|
</li>
|
|
<li>
|
|
<a href="mailto:baz@mail.org">baz</a>
|
|
</li>
|
|
</ul>
|