diff options
author | Jeremy Kemper <jeremy@bitsweat.net> | 2007-09-24 05:43:59 +0000 |
---|---|---|
committer | Jeremy Kemper <jeremy@bitsweat.net> | 2007-09-24 05:43:59 +0000 |
commit | e711d8fade2a47e4a709fa3eb4b8dd7af6f6ac08 (patch) | |
tree | e372b3807c822d37b2bd24495242bd16459379d6 /actionpack/lib | |
parent | cb5b8a7f055966c1f3e2d65d09c1b914e82d2c39 (diff) | |
download | rails-e711d8fade2a47e4a709fa3eb4b8dd7af6f6ac08.tar.gz rails-e711d8fade2a47e4a709fa3eb4b8dd7af6f6ac08.tar.bz2 rails-e711d8fade2a47e4a709fa3eb4b8dd7af6f6ac08.zip |
escape_once uses negative lookahead to avoid double-escaping instead of a second gsub
git-svn-id: http://svn-commit.rubyonrails.org/rails/trunk@7606 5ecf4fe2-1ee6-0310-87b1-e25e094e27de
Diffstat (limited to 'actionpack/lib')
-rw-r--r-- | actionpack/lib/action_view/helpers/tag_helper.rb | 7 |
1 files changed, 1 insertions, 6 deletions
diff --git a/actionpack/lib/action_view/helpers/tag_helper.rb b/actionpack/lib/action_view/helpers/tag_helper.rb index f222e43adc..963f494760 100644 --- a/actionpack/lib/action_view/helpers/tag_helper.rb +++ b/actionpack/lib/action_view/helpers/tag_helper.rb @@ -94,7 +94,7 @@ module ActionView # escape_once("<< Accept & Checkout") # # => "<< Accept & Checkout" def escape_once(html) - fix_double_escape(html_escape(html.to_s)) + html.to_s.gsub(/[\"><]|&(?!([a-zA-Z]+|(#\d+));)/) { |special| ERB::Util::HTML_ESCAPE[special] } end private @@ -116,11 +116,6 @@ module ActionView end end - # Fix double-escaped entities, such as &amp;, &#123;, etc. - def fix_double_escape(escaped) - escaped.gsub(/&([a-z]+|(#\d+));/i) { "&#{$1};" } - end - def block_is_within_action_view?(block) eval("defined? _erbout", block.binding) end |