diff options
author | José Valim <jose.valim@gmail.com> | 2011-06-08 08:08:59 -0700 |
---|---|---|
committer | José Valim <jose.valim@gmail.com> | 2011-06-08 08:08:59 -0700 |
commit | 8bc4771291d899614143550ecff4815542e92442 (patch) | |
tree | 6b6656d194ed1faa386757f75b363ec8942e6bf9 /actionpack | |
parent | b937c76f0dede1d15795503e5500748655fd0123 (diff) | |
parent | bf2f039a93d1b5bacffcda14e2c58f39dfcf7fd4 (diff) | |
download | rails-8bc4771291d899614143550ecff4815542e92442.tar.gz rails-8bc4771291d899614143550ecff4815542e92442.tar.bz2 rails-8bc4771291d899614143550ecff4815542e92442.zip |
Merge pull request #1560 from sikachu/master-escapejs
Make escape_javascript happy to handle SafeBuffers
Diffstat (limited to 'actionpack')
-rw-r--r-- | actionpack/lib/action_view/helpers/javascript_helper.rb | 2 | ||||
-rw-r--r-- | actionpack/test/template/javascript_helper_test.rb | 7 |
2 files changed, 8 insertions, 1 deletions
diff --git a/actionpack/lib/action_view/helpers/javascript_helper.rb b/actionpack/lib/action_view/helpers/javascript_helper.rb index d7228bab67..8a6f2e84be 100644 --- a/actionpack/lib/action_view/helpers/javascript_helper.rb +++ b/actionpack/lib/action_view/helpers/javascript_helper.rb @@ -18,7 +18,7 @@ module ActionView # $('some_element').replaceWith('<%=j render 'some/element_template' %>'); def escape_javascript(javascript) if javascript - javascript.gsub(/(\\|<\/|\r\n|[\n\r"'])/) { JS_ESCAPE_MAP[$1] } + javascript.gsub(/(\\|<\/|\r\n|[\n\r"'])/) {|match| JS_ESCAPE_MAP[match] } else '' end diff --git a/actionpack/test/template/javascript_helper_test.rb b/actionpack/test/template/javascript_helper_test.rb index 538e0e9874..15bd6b4c47 100644 --- a/actionpack/test/template/javascript_helper_test.rb +++ b/actionpack/test/template/javascript_helper_test.rb @@ -30,6 +30,13 @@ class JavaScriptHelperTest < ActionView::TestCase assert_equal %(dont <\\/close> tags), j(%(dont </close> tags)) end + def test_escape_javascript_with_safebuffer + given = %('quoted' "double-quoted" new-line:\n </closed>) + expect = %(\\'quoted\\' \\"double-quoted\\" new-line:\\n <\\/closed>) + assert_equal expect, escape_javascript(given) + assert_equal expect, escape_javascript(ActiveSupport::SafeBuffer.new(given)) + end + def test_button_to_function assert_dom_equal %(<input type="button" onclick="alert('Hello world!');" value="Greeting" />), button_to_function("Greeting", "alert('Hello world!')") |