diff options
author | Jamis Buck <jamis@37signals.com> | 2006-06-05 15:30:09 +0000 |
---|---|---|
committer | Jamis Buck <jamis@37signals.com> | 2006-06-05 15:30:09 +0000 |
commit | 149f5cad856f14b53780619a3efc0258cdd4759b (patch) | |
tree | d8fa0449c888c57928acbf653e6f3f676be652db /actionpack/lib | |
parent | 2ffc84d23ff8f78bf43b277d64a4bcda51e932fc (diff) | |
download | rails-149f5cad856f14b53780619a3efc0258cdd4759b.tar.gz rails-149f5cad856f14b53780619a3efc0258cdd4759b.tar.bz2 rails-149f5cad856f14b53780619a3efc0258cdd4759b.zip |
Escape the entire path before trying to recognize it (closes #3671)
git-svn-id: http://svn-commit.rubyonrails.org/rails/trunk@4436 5ecf4fe2-1ee6-0310-87b1-e25e094e27de
Diffstat (limited to 'actionpack/lib')
-rw-r--r-- | actionpack/lib/action_controller/routing.rb | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/actionpack/lib/action_controller/routing.rb b/actionpack/lib/action_controller/routing.rb index e1ad27fc3a..0b8d9c0a73 100644 --- a/actionpack/lib/action_controller/routing.rb +++ b/actionpack/lib/action_controller/routing.rb @@ -502,7 +502,7 @@ module ActionController hangon = (default ? "|| #{default.inspect}" : "if match[#{next_capture}]") # All non code-related keys (such as :id, :slug) have to be unescaped as other CGI params - "params[:#{key}] = match[#{next_capture}] && CGI.unescape(match[#{next_capture}]) #{hangon}" + "params[:#{key}] = match[#{next_capture}] #{hangon}" end def optionality_implied? @@ -991,6 +991,7 @@ module ActionController end def recognize_path(path, environment={}) + path = CGI.unescape(path) routes.each do |route| result = route.recognize(path, environment) and return result end |