a5e08f7bcc
I installed the rails_xss plugin, for the main purpose of seeing what will break with Rails 3.0 (where the behaviour of the plugin is the default). I think I've fixed everything, but let me know if you see stuff that is HTML-escaped, which shouldn't be. As a side benefit, we now use Erubis, rather than ERB, to render templates. They tell me it's faster ...
17 lines
336 B
Plaintext
17 lines
336 B
Plaintext
<?js
|
|
var user = 'Erubis';
|
|
var list = ['<aaa>', 'b&b', '"ccc"'];
|
|
?>
|
|
<p>Hello @{user}@!</p>
|
|
<table>
|
|
<tbody>
|
|
<?js var i; ?>
|
|
<?js for (i = 0; i < list.length; i++) { ?>
|
|
<tr bgcolor="@{i % 2 == 0 ? '#FFCCCC' : '#CCCCFF'}@">
|
|
<td>@{i + 1}@</td>
|
|
<td>@{list[i]}@</td>
|
|
</tr>
|
|
<?js } ?>
|
|
</tbody>
|
|
</table>
|