This project is archived and is in readonly mode.
Content_tag_string Sanitizes Possibly Unsafe HTML
-
Todd Sundsted
- Tag changed from content_tag, content_tag_string, html_safe to 2.3.5, content_tag, content_tag_string, html_safe
-
Todd Sundsted
- Tag changed from 2.3.5, content_tag, content_tag_string, html_safe to 2, content_tag, content_tag_string, html_safe
I committed the following patch to my fork of rails_xss, which handles all of the problems I've come across. Needs testing against other reported issues:
http://github.com/toddsundsted/rails_xss/commit/2df604fdf86200c80f7...
module ActionView module Helpers module TagHelper private def content_tag_string(name, content, options, escape = true) tag_options = tag_options(options, escape) if options content = ERB::Util.h(content) unless content.html_safe? "<#{name}#{tag_options}>#{content}</#{name}>".html_safe! end end end end -
José Valim
- Assigned user set to Michael Koziarski
-
Rohit Arondekar
Any updates to this ticket? Is this still an issue?
-
Santiago Pastorino
Todd the current code of rails_xss escapes the content as you are doing here ... take a look and please reply the ticket so we can close it ;).
http://github.com/rails/rails_xss/blob/master/lib/rails_xss/action_... -
Todd Sundsted
Thanks, guys! Will do.
-
Todd Sundsted
Everything looks good.
I tested with Rails 2.3.8 and the latest Erubis.
> x = '<script>alert("pwned")</script>' => "<script>alert(\"pwned\")</script>" > x.html_safe? => nil > y = helper.content_tag("div", x) => "<div><script>alert("pwned")</script></div>" > x = x.html_safe => "<script>alert(\"pwned\")</script>" > x.html_safe? => true > y = helper.content_tag("div", x) => "<div><script>alert(\"pwned\")</script></div>"Thanks again!
-
José Valim
- State changed from new to resolved
-
Andrea Campi
- Tag changed from 2, content_tag, content_tag_string, html_safe to 2-3-stable, content_tag, content_tag_string, html_safe
- Importance changed from to Low