diff options
author | Aaron Patterson <aaron.patterson@gmail.com> | 2016-08-11 10:40:42 -0700 |
---|---|---|
committer | Aaron Patterson <aaron.patterson@gmail.com> | 2016-08-11 10:40:42 -0700 |
commit | 5efc4ec4d997cb5f491a7dd79dd94779d08cf80d (patch) | |
tree | c102edcfc9b5f8f85bac64520234a804643066c3 /actionpack/lib | |
parent | d4a1b33a2ab6703124926fbf805d77ef753e1b87 (diff) | |
parent | ebc3639139d21eeb8452edb28ce62530cc075198 (diff) | |
download | rails-5efc4ec4d997cb5f491a7dd79dd94779d08cf80d.tar.gz rails-5efc4ec4d997cb5f491a7dd79dd94779d08cf80d.tar.bz2 rails-5efc4ec4d997cb5f491a7dd79dd94779d08cf80d.zip |
Merge branch '3-2-22-3' into 3-2-stable
* 3-2-22-3:
bumping version
ensure tag/content_tag escapes " in attribute vals
Diffstat (limited to 'actionpack/lib')
-rw-r--r-- | actionpack/lib/action_pack/version.rb | 2 | ||||
-rw-r--r-- | actionpack/lib/action_view/helpers/tag_helper.rb | 15 |
2 files changed, 12 insertions, 5 deletions
diff --git a/actionpack/lib/action_pack/version.rb b/actionpack/lib/action_pack/version.rb index 4fdf8cbf91..9c08a5d9a6 100644 --- a/actionpack/lib/action_pack/version.rb +++ b/actionpack/lib/action_pack/version.rb @@ -3,7 +3,7 @@ module ActionPack MAJOR = 3 MINOR = 2 TINY = 22 - PRE = "2" + PRE = "3" STRING = [MAJOR, MINOR, TINY, PRE].compact.join('.') end diff --git a/actionpack/lib/action_view/helpers/tag_helper.rb b/actionpack/lib/action_view/helpers/tag_helper.rb index 7f58a27d6a..34741b8d79 100644 --- a/actionpack/lib/action_view/helpers/tag_helper.rb +++ b/actionpack/lib/action_view/helpers/tag_helper.rb @@ -141,20 +141,27 @@ module ActionView unless v.is_a?(String) || v.is_a?(Symbol) || v.is_a?(BigDecimal) v = v.to_json end - v = ERB::Util.html_escape(v) if escape - attrs << %(data-#{k.to_s.dasherize}="#{v}") + attrs << tag_option("data-#{k.to_s.dasherize}", v, escape) end elsif BOOLEAN_ATTRIBUTES.include?(key) attrs << %(#{key}="#{key}") if value elsif !value.nil? final_value = value.is_a?(Array) ? value.join(" ") : value - final_value = ERB::Util.html_escape(final_value) if escape - attrs << %(#{key}="#{final_value}") + attrs << tag_option(key, value, escape) end end " #{attrs.sort * ' '}".html_safe unless attrs.empty? end end + + def tag_option(key, value, escape) + if value.is_a?(Array) + value = escape ? safe_join(value, " ") : value.join(" ") + else + value = escape ? ERB::Util.html_escape(value) : value + end + %(#{key}="#{value.gsub(/"/, '"'.freeze)}") + end end end end |