Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | Removed Array#safe_join in AS core_ext and moved it to a view helper with ↵ | Josh Kalderimis | 2011-02-10 | 2 | -21/+55 | |
| | | | | the same same. | |||||
* | Change the CSRF whitelisting to only apply to get requests | Michael Koziarski | 2011-02-08 | 1 | -136/+75 | |
| | | | | | | | | Unfortunately the previous method of browser detection and XHR whitelisting is unable to prevent requests issued from some Flash animations and Java applets. To ease the work required to include the CSRF token in ajax requests rails now supports providing the token in a custom http header: X-CSRF-Token: ... This fixes CVE-2011-0447 | |||||
* | Use Mime::Type references. | José Valim | 2011-02-08 | 3 | -1/+17 | |
| | ||||||
* | Ensure render is case sensitive even on systems with case-insensitive ↵ | José Valim | 2011-02-08 | 1 | -0/+10 | |
| | | | | | | filesystems. This fixes CVE-2011-0449 | |||||
* | Be sure to javascript_escape the email address to prevent apostrophes ↵ | Michael Koziarski | 2011-02-08 | 1 | -4/+5 | |
| | | | | | | inadvertently causing javascript errors. This fixes CVE-2011-0446 | |||||
* | Add tests showing the LH issue #6381: fields_for with inline blocks and ↵ | Carlos Antonio da Silva | 2011-02-08 | 1 | -1/+85 | |
| | | | | | | nested attributes already persisted Signed-off-by: Santiago Pastorino <santiago@wyeworks.com> | |||||
* | cleaning up some warnings on 1.9.3 | Aaron Patterson | 2011-02-07 | 8 | -27/+25 | |
| | ||||||
* | put authenticity_token option in parity w/ remote | Dan Pickett | 2011-02-06 | 1 | -2/+2 | |
| | | | | | | [#6228 state:committed] Signed-off-by: Santiago Pastorino <santiago@wyeworks.com> | |||||
* | Allow page_cache_directory to be set as a Pathname | Andre Arko | 2011-02-06 | 1 | -0/+11 | |
| | | | | | | For example, page_cache_directory = Rails.root.join("public/cache") Signed-off-by: Santiago Pastorino <santiago@wyeworks.com> | |||||
* | Added tests for form_for and an authenticity_token option. Added docs for ↵ | Timothy N. Tsvetkov | 2011-02-05 | 1 | -0/+18 | |
| | | | | | | | | for_for and authenticity_token option. Added section to form helpers guide about forms for external resources and new authenticity_token option for form_tag and form_for helpers. [#6228 state:committed] Signed-off-by: Santiago Pastorino <santiago@wyeworks.com> | |||||
* | fixed bug with nested resources within shallow scope | german | 2011-02-04 | 1 | -0/+62 | |
| | | | | | | [#6372 state:committed] Signed-off-by: Santiago Pastorino <santiago@wyeworks.com> | |||||
* | removing generation of id in submit helper | Franco Brusatti | 2011-02-03 | 1 | -6/+6 | |
| | | | | | | [#6369 state:committed] Signed-off-by: Santiago Pastorino <santiago@wyeworks.com> | |||||
* | Add a test for 'render :layout' | Anton Astashov | 2011-02-03 | 2 | -0/+9 | |
| | | | | | | | | | To make sure it will show block contents if it is placed after 'render :partial' [#5557 state:resolved] Signed-off-by: Santiago Pastorino <santiago@wyeworks.com> | |||||
* | Protocol-relative URL support. | Stephen Celis | 2011-02-02 | 1 | -1/+14 | |
| | | | | | | [#5774 state:committed] Signed-off-by: Santiago Pastorino <santiago@wyeworks.com> | |||||
* | add test to check class is being escaped in form_class | Santiago Pastorino | 2011-02-01 | 1 | -0/+4 | |
| | ||||||
* | Allow customization of form class for button_to | Andrei Bocan | 2011-02-01 | 1 | -0/+4 | |
| | | | | Signed-off-by: Santiago Pastorino <santiago@wyeworks.com> | |||||
* | auto_link: avoid recognizing full width chars as a part of URI scheme | Akira Matsuda | 2011-02-01 | 1 | -1/+7 | |
| | | | | | | | | fixes regression by http://github.com/rails/rails/commit/133ada6ab0f0cb7bef2bd40dbc18f2d5bc6b964e [#5503 state:committed] Signed-off-by: Santiago Pastorino <santiago@wyeworks.com> | |||||
* | Accept String value for render_partial :as option | Akira Matsuda | 2011-02-01 | 1 | -1/+6 | |
| | | | | | | [#6222 state:committed] Signed-off-by: Santiago Pastorino <santiago@wyeworks.com> | |||||
* | render_to_string must ensure that response_body | Neeraj Singh | 2011-01-25 | 1 | -0/+10 | |
| | | | | | | | | is nil [ #5875 state:resolved] Signed-off-by: José Valim <jose.valim@gmail.com> | |||||
* | A patch so that http status codes are still included in logs even during an ↵ | Doug Fales | 2011-01-25 | 1 | -0/+15 | |
| | | | | | | exception [#6333 state:resolved] Signed-off-by: José Valim <jose.valim@gmail.com> | |||||
* | use spec compliant YAML | Aaron Patterson | 2011-01-21 | 1 | -1/+1 | |
| | ||||||
* | Add tld_length option when using domain :all in cookies | brainopia | 2011-01-21 | 1 | -0/+36 | |
| | | | | Signed-off-by: José Valim <jose.valim@gmail.com> | |||||
* | Support list of possible domains for cookies | brainopia | 2011-01-21 | 1 | -0/+45 | |
| | | | | Signed-off-by: José Valim <jose.valim@gmail.com> | |||||
* | Solve SystemStackError when changing locale inside ActionMailer [#5329 ↵ | José Valim | 2011-01-19 | 1 | -1/+1 | |
| | | | | state:resolved] | |||||
* | removing usesless variable assignments | Aaron Patterson | 2011-01-18 | 2 | -16/+14 | |
| | ||||||
* | Merge branch 'template_error' into merge | Aaron Patterson | 2011-01-18 | 1 | -0/+13 | |
|\ | | | | | | | | | | | * template_error: Ensure original exception message is present in both Template::Error#message and Template::Error#inspect. ActiveSupport::Deprecation.silence no longer needed. | |||||
| * | Ensure original exception message is present in both Template::Error#message ↵ | John Firebaugh | 2010-10-29 | 1 | -0/+13 | |
| | | | | | | | | | | | | and Template::Error#inspect. Previously, #inspect would produce #<ActionView::Template::Error: ActionView::Template::Error>, which is not very useful. | |||||
* | | Issue one Cache#read command instead of two in the case of a fragment cache hit | Christos Trochalakis | 2011-01-18 | 1 | -4/+4 | |
| | | ||||||
* | | fixing space errors | Aaron Patterson | 2011-01-17 | 1 | -1/+1 | |
| | | ||||||
* | | fixing wrong test | Aaron Patterson | 2011-01-17 | 1 | -1/+1 | |
| | | ||||||
* | | button_tag should escape it content | Santiago Pastorino | 2011-01-12 | 1 | -0/+7 | |
| | | ||||||
* | | Allow view in AV::TestCase to access it's controller helpers methods | Santiago Pastorino | 2011-01-12 | 1 | -0/+21 | |
| | | ||||||
* | | authenticity_token option for form_tag [#2988 state:resolved] | Jakub Kuźma | 2011-01-09 | 1 | -0/+18 | |
| | | ||||||
* | | Improve select helpers by allowing a selected value of false. This is ↵ | John Allison | 2011-01-09 | 1 | -8/+24 | |
| | | | | | | | | useful when using a select helper with a boolean attribute, and the attribute is false. (e.g. f.select :allow_comments) | |||||
* | | HTML5 button_tag helper | Rizwan Reza | 2011-01-09 | 1 | -0/+28 | |
| | | | | | | | | | | | | | | | | This tag is similar in nature to submit_tag, but allows more control. It also doesn't submit if submit type isn't used, allowing JavaScript to control the flow where required. For more information: http://www.whatwg.org/specs/web-apps/current-work/multipage/the-button-element.html#the-button-element | |||||
* | | Recreate symlink in layouts for tests | Piotr Sarnacki | 2010-12-31 | 1 | -0/+1 | |
| | | ||||||
* | | Don't be so picky on MissingTemplate error details, this fails randomly on ↵ | Piotr Sarnacki | 2010-12-31 | 1 | -4/+3 | |
| | | | | | | | | 1.8.7 because of not ordered hash | |||||
* | | added tests for the MissingTemplate exception message. | Nick Sutterer | 2010-12-31 | 1 | -0/+21 | |
| | | ||||||
* | | ActionController::Base.helpers.sanitize ignores case in protocol | Timothy N. Tsvetkov | 2010-12-30 | 2 | -1/+7 | |
| | | | | | | | | | | | | [#6044 state:committed] Signed-off-by: Santiago Pastorino <santiago@wyeworks.com> | |||||
* | | process_action accepts multiple args, even with Callbacks. | Nick Sutterer | 2010-12-29 | 1 | -0/+21 | |
| | | ||||||
* | | Speed up template inheritance and remove template inheritance option | wycats | 2010-12-26 | 1 | -12/+0 | |
| | | ||||||
* | | A bunch of cleanup on the inherited template patch | wycats | 2010-12-26 | 1 | -1/+1 | |
| | | ||||||
* | | all tests pass | artemave | 2010-12-26 | 4 | -33/+33 | |
| | | ||||||
* | | #948 make template inheritance optional | artemave | 2010-12-26 | 1 | -0/+11 | |
| | | ||||||
* | | #948 template_inheritance | artemave | 2010-12-26 | 4 | -11/+75 | |
| | | ||||||
* | | Don't deprecate to_prepare. | José Valim | 2010-12-23 | 1 | -5/+7 | |
| | | ||||||
* | | Clean up callbacks should also be called on exceptions. | José Valim | 2010-12-23 | 1 | -0/+14 | |
| | | ||||||
* | | Allow registering javascript/stylesheet_expansions to existing symbols | Santiago Pastorino | 2010-12-22 | 1 | -0/+19 | |
| | | ||||||
* | | Do not use the same hash instance for expansions [#6114 state:resolved] | Piotr Sarnacki | 2010-12-22 | 1 | -0/+8 | |
| | | | | | | | | | | Using the same hash instance makes using the same expansions for both javascripts and stylesheets. | |||||
* | | Small changes on AD::Reloader. | José Valim | 2010-12-20 | 1 | -20/+5 | |
| | |