This project is archived and is in readonly mode.
[PATCH] simple_format output should not be HTML-escaped in Rails 3
-
Stephen Celis
- Assigned user set to Pratik
Applies cleanly, but doesn't work as intended due to safe_concat.
Here's an additional patch (to retain new test cases) that uses String#insert for the final, closing "
". +1 otherwise. -
Stephen Celis
I guess Lighthouse is raw(). That was supposed to read "closing '</p>'".
-
Jeremy Kemper
- State changed from new to open
- Milestone cleared.
-
Santiago Pastorino
- Assigned user changed from Pratik to Yehuda Katz (wycats)
Here is the correct patch
-
Santiago Pastorino
New patch after DHH change
-
Santiago Pastorino
- No changes were found…
-
Repository
- State changed from open to committed
(from [4158282e32bf0a7d9fbb1a7669ade2226f909b12]) simple_format returns a safe buffer escaping unsafe input [Santiago Pastorino] (Closes #3767 [PATCH] simple_format output should not be HTML-escaped in Rails 3)
Signed-off-by: David Heinemeier Hansson david@loudthinking.com
http://github.com/rails/rails/commit/4158282e32bf0a7d9fbb1a7669ade2... -
David Reese
This should not have been applied to Rails 2.3! When moving to Rails 3, I would expect more escaping by default, but this change will jump out and bite many of us running "2.3 stable".
As Adam wrote, "Since the default behavior of Rails 3...".
Also, a documentation change would have been helpful -- at least mentioning that the incoming string will be escaped.
-
Santiago Pastorino
- Milestone set to 2.3.6
- State changed from committed to open
- Assigned user changed from Yehuda Katz (wycats) to Jeremy Kemper
David you're right, we should escape this on rails_xss, sorry my bad.
On rails
http://github.com/spastorino/rails/commit/571593da45834dae10b20cbd8...On rails_xss (I can merge this one)
http://github.com/spastorino/rails_xss/commit/96cb0059f79d62e3660a9... -
Santiago Pastorino
I've removed a test that i shouldn't here is the right patch with [#OMG] thing
-
Repository
- State changed from open to committed
(from [adcfb4e8bd886fe9d14a9b97afdb9182d8abdc95]) simple_format should return html_safe but not escape text, that's for rails_xss plugin [#3767 [PATCH] simple_format output should not be HTML-escaped in Rails 3 state:committed]
Signed-off-by: Jeremy Kemper jeremy@bitsweat.net
http://github.com/rails/rails/commit/adcfb4e8bd886fe9d14a9b97afdb91...
