Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

truncate should always return unsafe strings

#4878

As mentioned in #4825 Some text helper methods inappropriately calling "sanitize" the change to using santize in truncate has broken some valid use cases. e.g. descriptions such as:

  <script> tags not working in admin section

Instead the helper should simply return the strings as unsafe, and let the user either mark them as raw() or rely on the default escaping.

We can't use the html_safety of the input to determine whether to return a safe string because of cases like this:

  <%= truncate(h("wtf&"), 4) %>

Reported by Michael Koziarski · June 16th, 2010 @ 10:25 PM

State: committed
Milestone: 3.0.2
Assigned to: Santiago Pastorino Santiago Pastorino
Importance: Low

Activity

  1. Wincent Colaiuta
    Wincent Colaiuta

    Proposed fix pushed to the "ticket4878" branch of my fork:

    http://github.com/wincent/rails/tree/ticket4878

    Specifically, this commit:

    http://github.com/wincent/rails/commit/157db6a2f7df1924f0c738fa4ac1...

    I've modified the tests, but I am having trouble running the test suite on this machine so I'd appreciate it if someone could confirm that this is correct.

    June 17th, 2010 @ 07:43 AM

  2. Wincent Colaiuta
    Wincent Colaiuta

    Ok, fixed the problems in my test environment. Confirmed that everything passes.

    June 17th, 2010 @ 08:02 AM

  3. Wincent Colaiuta
  4. Santiago Pastorino
    Santiago Pastorino
    • State changed from new to verified

    +1 yesterday i did the patch and is the same as yours, but i'm attaching the patch again maintaining Wincent as the author of the original patch with one more test for excerpt method that shouldn't return safe too, so please someone of the core go ahead and apply it ;).

    June 17th, 2010 @ 11:40 AM

  5. Repository
  6. DHH
    DHH
    • State changed from verified to committed

    June 17th, 2010 @ 03:42 PM

  7. Wincent Colaiuta
    Wincent Colaiuta

    Still not fixed though.

    Commit 7240a960 contains only Santiago's additional test for the "excerpt" method.

    Missing is my patch, the one which actually addresses the subject of this ticket ("truncate should always return unsafe strings").

    June 17th, 2010 @ 03:46 PM

  8. Rohit Arondekar
  9. Wincent Colaiuta
  10. Jeremy Kemper
    Jeremy Kemper
    • Milestone set to 3.0.2
    • Importance changed from to Low

    October 15th, 2010 @ 11:01 PM