xss - Rails 2.3.5 with rails_xss escaping content_for yielded content -


The rail has been upgraded to just 2.3.5 to look lovely, but I have seen a major problem with it.

I have tried hacking it in any of the following ways but they do not work:

  & lt;% @ content_for_foo.html_clean! -% & gt; & Lt;% = Raw raw: foo% & gt;     

Try & lt;% = raw produce: foo % & Gt;


Comments

Popular posts from this blog

c# - How to capture HTTP packet with SharpPcap -

php - Multiple Select with Explode: only returns the word "Array" -

php - jQuery AJAX Post not working -