This project is archived and is in readonly mode.
Field_set_tag doesn't escape the legend
-
Michael Koziarski
- Tag changed from 2-3-stable, patch, xss to patch, xss
- Milestone cleared.
Can't apply this to 2-3-stable as it'll break people's apps who have already added h() calls, we can fix it in master though where h() is idempotent.
-
Santiago Pastorino
- State changed from new to wontfix
On 3.0 is working that way.
It's automatically escaped because you start with a SafeBuffer and the output builder concat that legend with the SafeBuffer he manages using this method from SafeBuffermodule ActiveSupport #:nodoc: class SafeBuffer < String def concat(value) if value.html_safe? super(value) else super(ERB::Util.h(value)) end end alias << concat end end -
Santiago Pastorino
- State changed from wontfix to open
- Milestone set to 2.3.6
That's fixed with http://github.com/spastorino/rails/commit/84fd5400c065b6ca659a50354...
-
Santiago Pastorino
- State changed from open to wontfix
This is going to be fixed on github.com/rails/rails_xss
