mirror of
https://github.com/github/rails.git
synced 2026-01-30 00:38:00 -05:00
Fix double-escaped entities, such as &, {, etc. [Rick]
git-svn-id: http://svn-commit.rubyonrails.org/rails/trunk@5321 5ecf4fe2-1ee6-0310-87b1-e25e094e27de
This commit is contained in:
@@ -1,5 +1,7 @@
|
||||
*SVN*
|
||||
|
||||
* Fix double-escaped entities, such as &, {, etc. [Rick]
|
||||
|
||||
* Fix deprecation warnings when rendering the template error template. [Nicholas Seckar]
|
||||
|
||||
* Fix routing to correctly determine when generation fails. Closes #6300. [psross].
|
||||
|
||||
@@ -34,7 +34,7 @@ module ActionView
|
||||
private
|
||||
def tag_options(options)
|
||||
cleaned_options = convert_booleans(options.stringify_keys.reject {|key, value| value.nil?})
|
||||
' ' + cleaned_options.map {|key, value| %(#{key}="#{html_escape(value.to_s)}")}.sort * ' ' unless cleaned_options.empty?
|
||||
' ' + cleaned_options.map {|key, value| %(#{key}="#{fix_double_escape(html_escape(value.to_s))}")}.sort * ' ' unless cleaned_options.empty?
|
||||
end
|
||||
|
||||
def convert_booleans(options)
|
||||
@@ -45,6 +45,11 @@ module ActionView
|
||||
def boolean_attribute(options, attribute)
|
||||
options[attribute] ? options[attribute] = attribute : options.delete(attribute)
|
||||
end
|
||||
|
||||
# Fix double-escaped entities, such as &, {, etc.
|
||||
def fix_double_escape(escaped)
|
||||
escaped.gsub(/&([a-z]+|(#\d+));/i) { "&#{$1};" }
|
||||
end
|
||||
end
|
||||
end
|
||||
end
|
||||
|
||||
@@ -38,4 +38,16 @@ class TagHelperTest < Test::Unit::TestCase
|
||||
def test_cdata_section
|
||||
assert_equal "<![CDATA[<hello world>]]>", cdata_section("<hello world>")
|
||||
end
|
||||
|
||||
def test_double_escaping_attributes
|
||||
['1&2', '1 < 2', '“test“'].each do |escaped|
|
||||
assert_equal %(<a href="#{escaped}" />), tag('a', :href => escaped)
|
||||
end
|
||||
end
|
||||
|
||||
def test_skip_invalid_escaped_attributes
|
||||
['&1;', 'dfa3;', '& #123;'].each do |escaped|
|
||||
assert_equal %(<a href="#{escaped.gsub /&/, '&'}" />), tag('a', :href => escaped)
|
||||
end
|
||||
end
|
||||
end
|
||||
|
||||
Reference in New Issue
Block a user