Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Fix issue where TextHelper#simple_format was calling missing 'raw' method | Mario Visic | 2013-12-05 | 1 | -0/+2 |
| | |||||
* | Remove the escaping skip | Rafael Mendonça França | 2013-12-03 | 1 | -1/+1 |
| | | | | | We are generating safe strings in the paragraph, so we can escape the tags | ||||
* | Ensure simple_format escapes its html attributes | Michael Koziarski | 2013-12-02 | 1 | -1/+1 |
| | | | | | | | | | | The previous behavior equated the sanitize option for simple_format with the escape option of content_tag, however these are two distinct concepts. This fixes CVE-2013-6416 Conflicts: actionview/lib/action_view/helpers/text_helper.rb | ||||
* | fix simple_format escapes own output when sanitize is set to true | pseidemann | 2013-11-08 | 1 | -1/+1 |
| | |||||
* | Cleanup of excerpt helper | Paul Nikitochkin | 2013-09-06 | 1 | -2/+3 |
| | | | | | * replaced String concatenation by joining * separator has default value to '', even it is nil | ||||
* | Removed an unnecessary loop - it kills performance on large texts. | Jan Szumiec | 2013-08-03 | 1 | -4/+6 |
| | |||||
* | Change from `map` => `map!` and `collect!` to save creation of extra array. | Vipul A M | 2013-07-31 | 1 | -2/+2 |
| | |||||
* | Fix simple_format output example ending tag | Matt Bridges | 2013-07-09 | 1 | -1/+1 |
| | |||||
* | Move actionpack/lib/action_view* into actionview/lib | Piotr Sarnacki | 2013-06-20 | 1 | -0/+442 |