Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

I18n translated strings are html-escaped in views

#5014

I don't know if this is expected behavior or an unexpected by-product of Rails now auto-escaping all strings in views, but it bit me when upgrading my app to Rails 3 beta4. Best explained here:

http://gehling.dk/2010/06/avoid-html-escaping-i18n-strings-in-rails-3/

If the above fix is not added, all entries like <%=t(:some_key)%> have to be rewritten to <%=raw(t(:some_key))%> or <%=t(:some_key).html_safe%>

I will be happy to supply a patch, if you think this is a bug.

/Carsten

Reported by Carsten Gehling · June 30th, 2010 @ 09:12 AM

State: invalid
Milestone: none
Assigned to: nobody
Importance: Low

Activity

  1. Carsten Gehling
    Carsten Gehling
    • Tag changed from i18n html_safe to html_safe, i18n

    June 30th, 2010 @ 09:13 AM

  2. Carsten Gehling
    Carsten Gehling
    • Tag changed from html_safe, i18n to 3.x, html_safe, i18n

    June 30th, 2010 @ 09:14 AM

  3. Jan De Poorter
    Jan De Poorter

    In my opinion it should be more "secure":

    @@@ruby

    This should be html_safe by default

    <%= I18n.t(:hello_user) %>

    This should not be html_safe

    <%= I18n.t(:user_title, :username => @user.name) %>

    
    So basically if there is no interpolation it should be html_safe, if there is interpolation it should be escaped (because we all know 1 user with name <script>alert('I hax0red you')</script> right)
    

    June 30th, 2010 @ 09:48 AM

  4. Jan De Poorter
    Jan De Poorter

    sorry for the bad formatting on my part there.

    June 30th, 2010 @ 09:50 AM

  5. Carsten Gehling
    Carsten Gehling

    Ah yes of course. :-)

    I am not sure that it is a good idea to patch it then. It'll probably make things more confusing. Shouldn't a developer be able to expect just one kind of output from I18n.translate?

    I'm really in doubt about this.

    /Carsten

    June 30th, 2010 @ 10:09 AM

  6. José Valim
    José Valim
    • State changed from new to invalid
    • Importance changed from to Low

    This is on purpose. Btw, if you append _html to the translation, it's marked as safe. That said:

    t(".title_html")

    It will be marked as safe and won't be escaped.

    June 30th, 2010 @ 12:08 PM

  7. Carsten Gehling