Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

:include_blank and :prompt options for #select not HTML safe

#5099

String options :include_blank and :prompt options are not HTML-escaped or checked for safety before being concatenated with markup.

select("post", "person_id", Person.all.collect {|p| [ p.name, p.id ] }, {:include_blank => '<None>'})

produces:

<select name="post[person_id]">
     <option value=""><None></option>
     <option value="1">David</option>
     <option value="2" selected="selected">Sam</option>
     <option value="3">Tobias</option>
</select>

It should produce:

<select name="post[person_id]">
     <option value="">&lt;None&gt;</option>
     <option value="1">David</option>
     <option value="2" selected="selected">Sam</option>
     <option value="3">Tobias</option>
</select>

Reported by John Firebaugh · July 12th, 2010 @ 08:36 PM

State: resolved
Milestone: 3.x
Assigned to: José Valim José Valim
Importance: Low

Activity

  1. Rohit Arondekar
    Rohit Arondekar
    • Milestone set to 3.x
    • State changed from new to open
    • Tag set to actionpack, formtaghelper, select
    • Importance changed from to Low

    Can you write a failing test and a patch?

    July 13th, 2010 @ 01:30 PM

  2. Ivan Torres (mexpolk)
    Ivan Torres (mexpolk)
    • Tag changed from actionpack, formtaghelper, select to actionpack, formoptionshelper, grouped_options_for_select, select

    confirmed... here's the patch

    July 13th, 2010 @ 04:11 PM

  3. Rohit Arondekar
    Rohit Arondekar

    The change looks good but you'll need to add a failing test too.

    July 14th, 2010 @ 01:27 AM

  4. Ivan Torres (mexpolk)
  5. Rohit Arondekar
    Rohit Arondekar
    • Assigned user set to José Valim

    July 14th, 2010 @ 12:36 PM

  6. Repository