xss - Rails 2.3.5 with rails_xss escaping content_for yielded content -
The rail has been upgraded to just 2.3.5 to look lovely, but I have seen a major problem with it.
I have tried hacking it in any of the following ways but they do not work:
& lt;% @ content_for_foo.html_clean! -% & gt; & Lt;% = Raw raw: foo% & gt;
Try & lt;% = raw produce: foo % & Gt;
Comments
Post a Comment