Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

ERB in html/plain is HTML escaped

#6067

With Rails 3, ERB blocks with unsafe strings are automagically HTML escaped. This is great when one wants to output HTML, but it just does not make sense for example in a text/plain email template, where there's no such escaping syntax (none at all, for the example of text/plain).

I think a different escaping procedure should be chosen based on the MIME type served and no automatic escaping should take place for text/plain.

My expectation would be:

my_mail.text.erb

<%= "I <3 Rails" %>

produces

I <3 Rails

my_mail.html.erb

<%= "I <3 Rails" %>

produces

I &lt;3 Rails

My point isn't only that I don't want to use raw() in text templates, but also that automatic escaping might be great for other MIME types, but then again it would not necessarily be HTML escaping.

Reported by Jan · November 25th, 2010 @ 08:17 PM

State: duplicate
Milestone: none
Assigned to: nobody
Importance: Low

Activity

  1. Jan
    Jan

    "html/plain" in the title should have read "text/plain". Sorry for the mistake.

    November 25th, 2010 @ 08:19 PM

  2. Santiago Pastorino