Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

There was a problem

This project is archived and is in readonly mode.

:include_blank and :prompt options for #select not HTML safe

#5099

String options :include_blank and :prompt options are not HTML-escaped or checked for safety before being concatenated with markup.

select("post", "person_id", Person.all.collect {|p| [ p.name, p.id ] }, {:include_blank => '<None>'})

produces:

<select name="post[person_id]">
     <option value=""><None></option>
     <option value="1">David</option>
     <option value="2" selected="selected">Sam</option>
     <option value="3">Tobias</option>
</select>

It should produce:

<select name="post[person_id]">
     <option value="">&lt;None&gt;</option>
     <option value="1">David</option>
     <option value="2" selected="selected">Sam</option>
     <option value="3">Tobias</option>
</select>

Reported by John Firebaugh · July 12th, 2010 @ 08:36 PM

State: resolved
Milestone: 3.x
Assigned to: José Valim José Valim
Importance: Low

Activity

  1. Rohit Arondekar
    Rohit Arondekar
    • Milestone set to 3.x
    • State changed from new to open
    • Tag set to actionpack, formtaghelper, select
    • Importance changed from to Low

    Can you write a failing test and a patch?

    July 13th, 2010 @ 01:30 PM

  2. Ivan Torres (mexpolk)
    Ivan Torres (mexpolk)
    • Tag changed from actionpack, formtaghelper, select to actionpack, formoptionshelper, grouped_options_for_select, select

    confirmed... here's the patch

    July 13th, 2010 @ 04:11 PM

  3. Rohit Arondekar
    Rohit Arondekar

    The change looks good but you'll need to add a failing test too.

    July 14th, 2010 @ 01:27 AM

  4. Ivan Torres (mexpolk)
  5. Rohit Arondekar
    Rohit Arondekar
    • Assigned user set to José Valim

    July 14th, 2010 @ 12:36 PM

  6. Repository