Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

Field_set_tag doesn't escape the legend

#3450

The field_set_tag doesn't escape the legend, but returns an html-safe string. I've patched it to escape it.

Reported by Bruno Michel · November 1st, 2009 @ 02:29 PM

State: wontfix
Milestone: 2.3.6
Assigned to: Michael Koziarski Michael Koziarski
Importance: Medium

Activity

  1. Michael Koziarski
    Michael Koziarski
    • Tag changed from 2-3-stable, patch, xss to patch, xss
    • Milestone cleared.

    Can't apply this to 2-3-stable as it'll break people's apps who have already added h() calls, we can fix it in master though where h() is idempotent.

    November 30th, 2009 @ 08:34 PM

  2. Santiago Pastorino
    Santiago Pastorino
    • State changed from new to wontfix

    On 3.0 is working that way.
    It's automatically escaped because you start with a SafeBuffer and the output builder concat that legend with the SafeBuffer he manages using this method from SafeBuffer

    module ActiveSupport #:nodoc:
      class SafeBuffer < String
        def concat(value)
          if value.html_safe?
            super(value)
          else
            super(ERB::Util.h(value))
          end
        end
        alias << concat
      end
    end
    

    March 8th, 2010 @ 03:41 AM

  3. Santiago Pastorino
    Santiago Pastorino
    • State changed from wontfix to open
    • Milestone set to 2.3.6

    March 10th, 2010 @ 12:12 AM

  4. Santiago Pastorino
    Santiago Pastorino
    • State changed from open to wontfix

    This is going to be fixed on github.com/rails/rails_xss

    March 22nd, 2010 @ 02:50 AM