a5e08f7bcc
I installed the rails_xss plugin, for the main purpose of seeing what will break with Rails 3.0 (where the behaviour of the plugin is the default). I think I've fixed everything, but let me know if you see stuff that is HTML-escaped, which shouldn't be. As a side benefit, we now use Erubis, rather than ERB, to render templates. They tell me it's faster ...
9 lines
344 B
Ruby
9 lines
344 B
Ruby
require 'erubis'
|
|
eruby = Erubis::Eruby.new(File.read('template1.rhtml'))
|
|
items = ['foo', 'bar', 'baz']
|
|
x = 1
|
|
## local variable 'x' and 'eruby' are passed to template as well as 'items'!
|
|
print eruby.result(binding())
|
|
## local variable 'x' is changed unintendedly because it is changed in template!
|
|
puts "** debug: x=#{x.inspect}" #=> "baz"
|