This project is archived and is in readonly mode.
I18n translated strings are html-escaped in views
-
Carsten Gehling
- Tag changed from i18n html_safe to html_safe, i18n
-
Carsten Gehling
- Tag changed from html_safe, i18n to 3.x, html_safe, i18n
-
Jan De Poorter
In my opinion it should be more "secure":
@@@ruby
This should be html_safe by default
<%= I18n.t(:hello_user) %>
This should not be html_safe
<%= I18n.t(:user_title, :username => @user.name) %>
So basically if there is no interpolation it should be html_safe, if there is interpolation it should be escaped (because we all know 1 user with name <script>alert('I hax0red you')</script> right) -
Jan De Poorter
sorry for the bad formatting on my part there.
-
Carsten Gehling
Ah yes of course. :-)
I am not sure that it is a good idea to patch it then. It'll probably make things more confusing. Shouldn't a developer be able to expect just one kind of output from I18n.translate?
I'm really in doubt about this.
/Carsten
-
José Valim
- State changed from new to invalid
- Importance changed from to Low
This is on purpose. Btw, if you append _html to the translation, it's marked as safe. That said:
t(".title_html")
It will be marked as safe and won't be escaped.
-
Carsten Gehling
Okay, thanks.
/Carsten