aboutsummaryrefslogtreecommitdiffstats
path: root/actionpack/lib/action_controller/routing.rb
diff options
context:
space:
mode:
authorJamis Buck <jamis@37signals.com>2006-06-05 14:51:27 +0000
committerJamis Buck <jamis@37signals.com>2006-06-05 14:51:27 +0000
commit2ffc84d23ff8f78bf43b277d64a4bcda51e932fc (patch)
tree83deb19800270a95aa41ad6a5ede5e66bdc1b4a3 /actionpack/lib/action_controller/routing.rb
parent332fcfaf6bee6b3ae0911e9bbe24ded9af757868 (diff)
downloadrails-2ffc84d23ff8f78bf43b277d64a4bcda51e932fc.tar.gz
rails-2ffc84d23ff8f78bf43b277d64a4bcda51e932fc.tar.bz2
rails-2ffc84d23ff8f78bf43b277d64a4bcda51e932fc.zip
Make sure :id and friends are properly unescaped (closes #5275).
git-svn-id: http://svn-commit.rubyonrails.org/rails/trunk@4435 5ecf4fe2-1ee6-0310-87b1-e25e094e27de
Diffstat (limited to 'actionpack/lib/action_controller/routing.rb')
-rw-r--r--actionpack/lib/action_controller/routing.rb4
1 files changed, 3 insertions, 1 deletions
diff --git a/actionpack/lib/action_controller/routing.rb b/actionpack/lib/action_controller/routing.rb
index 9628c1f0ad..e1ad27fc3a 100644
--- a/actionpack/lib/action_controller/routing.rb
+++ b/actionpack/lib/action_controller/routing.rb
@@ -500,7 +500,9 @@ module ActionController
end
def match_extraction(next_capture)
hangon = (default ? "|| #{default.inspect}" : "if match[#{next_capture}]")
- "params[:#{key}] = match[#{next_capture}] #{hangon}"
+
+ # All non code-related keys (such as :id, :slug) have to be unescaped as other CGI params
+ "params[:#{key}] = match[#{next_capture}] && CGI.unescape(match[#{next_capture}]) #{hangon}"
end
def optionality_implied?