aboutsummaryrefslogtreecommitdiffstats
path: root/actionpack/lib/action_controller
diff options
context:
space:
mode:
authorRick Olson <technoweenie@gmail.com>2007-12-23 21:07:20 +0000
committerRick Olson <technoweenie@gmail.com>2007-12-23 21:07:20 +0000
commite781faddca7523c6b700d03887b6603488128ced (patch)
tree50802f1c857533726683095bfba84f374eadb7cb /actionpack/lib/action_controller
parent38f8252e2d0a109d1b833d6b289cd989e7bfffe4 (diff)
downloadrails-e781faddca7523c6b700d03887b6603488128ced.tar.gz
rails-e781faddca7523c6b700d03887b6603488128ced.tar.bz2
rails-e781faddca7523c6b700d03887b6603488128ced.zip
Fix HTML Sanitizer to allow trailing spaces in CSS style attributes. Closes #10566 [wesley.moxam]
git-svn-id: http://svn-commit.rubyonrails.org/rails/trunk@8485 5ecf4fe2-1ee6-0310-87b1-e25e094e27de
Diffstat (limited to 'actionpack/lib/action_controller')
-rw-r--r--actionpack/lib/action_controller/vendor/html-scanner/html/sanitizer.rb4
1 files changed, 2 insertions, 2 deletions
diff --git a/actionpack/lib/action_controller/vendor/html-scanner/html/sanitizer.rb b/actionpack/lib/action_controller/vendor/html-scanner/html/sanitizer.rb
index 1eb426aea1..12c8405101 100644
--- a/actionpack/lib/action_controller/vendor/html-scanner/html/sanitizer.rb
+++ b/actionpack/lib/action_controller/vendor/html-scanner/html/sanitizer.rb
@@ -107,7 +107,7 @@ module HTML
# gauntlet
if style !~ /^([:,;#%.\sa-zA-Z0-9!]|\w-\w|\'[\s\w]+\'|\"[\s\w]+\"|\([\d,\s]+\))*$/ ||
- style !~ /^(\s*[-\w]+\s*:\s*[^:;]*(;|$))*$/
+ style !~ /^(\s*[-\w]+\s*:\s*[^:;]*(;|$)\s*)*$/
return ''
end
@@ -170,4 +170,4 @@ module HTML
(value =~ /(^[^\/:]*):|(&#0*58)|(&#x70)|(%|&#37;)3A/ && !allowed_protocols.include?(value.split(protocol_separator).first))
end
end
-end \ No newline at end of file
+end