Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
| * | | | | Missing ActiveSupport require for calling String#first | Akira Matsuda | 2014-08-14 | 1 | -0/+1 | |
| |/ / / | ||||||
* | | | | Prepare for partial release. | Kasper Timm Hansen | 2014-08-17 | 1 | -3/+8 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | - Default to Rails::DeprecatedSanitizer in ActionView::Helpers::SanitizeHelper. - Add upgrade notes. - Add sanitizer to new applications Gemfiles. - Remove 'rails-dom-testing' as a dependency. | |||||
* | | | | Merge branch 'master' into loofah | Rafael Mendonça França | 2014-08-12 | 5 | -94/+92 | |
|\| | | | | | | | | | | | | | | | | | | | | | | | | | | | Conflicts: actionpack/CHANGELOG.md actionpack/test/controller/integration_test.rb actionview/CHANGELOG.md | |||||
| * | | | Fixed #select form builder helper to support block with html output | Bogdan Gusiev | 2014-08-05 | 1 | -1/+1 | |
| | |/ | |/| | ||||||
| * | | docs, cleanup mixed indents within `form_options_helper.rb` RDoc. | Yves Senn | 2014-07-29 | 1 | -81/+81 | |
| | | | | | | | | | | | | | | | | | | | | | [ci skip] This fixes the broken code block rendering and indents the examples within the parameter list. | |||||
| * | | docs, `select` and friends with `multiple=true` include a blank string. | Yves Senn | 2014-07-17 | 1 | -5/+3 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | [Jonas Baumann & Yves Senn] The submitted params from a select with `multiple: true` look as follows: ``` {post: {category: [""]}} {post: {category: ["", "Category 1", "Category 2"]}} ``` This is a follow up to #1552. | |||||
| * | | Fix broken list formatting [ci skip] | noinkling | 2014-07-17 | 1 | -5/+5 | |
| | | | ||||||
| * | | Merge pull request #16161 from jpawlyn/master | Andrew White | 2014-07-15 | 1 | -1/+1 | |
| |\ \ | | | | | | | | | Fix empty host for an asset url when asset_host proc returns nil | |||||
| | * | | Return an absolute instead of relative path from an asset url in the case of ↵ | Jolyon Pawlyn | 2014-07-15 | 1 | -1/+1 | |
| | | | | | | | | | | | | | | | | the `asset_host` proc returning nil | |||||
| * | | | Fix typos like `a html` to `an html` and 'an mail' to 'an email'. [ci skip] | Santosh Wadghule | 2014-07-14 | 1 | -1/+1 | |
| |/ / | ||||||
* | | | Use the plugin API to the getter and setters | Rafael Mendonça França | 2014-07-15 | 1 | -4/+4 | |
| | | | | | | | | | | | | | | | To avoid having to redefine these methods on the deprecated plugin we should be using the sanitizer_vendor API. | |||||
* | | | Merge pull request #11218 from kaspth/loofah-integration | Rafael Mendonça França | 2014-07-10 | 1 | -106/+59 | |
|\ \ \ | |/ / |/| | | | | | | | | | | | | | | | | | Loofah-integration Conflicts: actionpack/CHANGELOG.md actionview/CHANGELOG.md | |||||
| * | | Don't splat arguments to allowed tags or attributes. | Timm | 2014-06-16 | 1 | -2/+2 | |
| | | | ||||||
| * | | Change sanitizer_vendor to just be a method and reword documentation. | Timm | 2014-06-16 | 1 | -4/+5 | |
| | | | ||||||
| * | | Revert some stuff to use the new sanitizers. | Timm | 2014-06-16 | 1 | -6/+6 | |
| | | | ||||||
| * | | Add a layer of indirection making sanitizers pluggable. | Timm | 2014-06-16 | 1 | -3/+8 | |
| | | | ||||||
| * | | Delegate allowed tags and attributes setting to HTML::WhiteListSanitizer. | Timm | 2014-06-16 | 1 | -4/+4 | |
| | | | ||||||
| * | | Changed configuration documentation to no longer state it replaces a Set. | Timm | 2014-06-16 | 1 | -2/+2 | |
| | | | ||||||
| * | | Deprecate configurations and use allowed_tags and allowed_attributes on ↵ | Timm | 2014-06-16 | 1 | -99/+22 | |
| | | | | | | | | | | | | WhiteListSanitizer. | |||||
| * | | Made deprecation messages in sanitize_helper more clear. | Timm | 2014-06-16 | 1 | -3/+3 | |
| | | | ||||||
| * | | Completed integration of rails-html-sanitizer in SanitizeHelper. Deprecated ↵ | Timm | 2014-06-16 | 3 | -294/+19 | |
| | | | | | | | | | | | | protocol_separator accessors and bad_tags=. | |||||
| * | | Changed PermitScrubber's direction to bottom up to align better with ↵ | Timm | 2014-06-16 | 1 | -0/+1 | |
| | | | | | | | | | | | | Loofah's strip scrubber. | |||||
| * | | Now only requiring Loofah in the places where it is needed. | Timm | 2014-06-16 | 1 | -0/+2 | |
| | | | ||||||
| * | | Minor rewording in TargetScrubber documentation. | Timm | 2014-06-16 | 1 | -3/+3 | |
| | | | ||||||
| * | | Now returning html if html is blank? in FullSanitizer and ↵ | Timm | 2014-06-16 | 1 | -1/+3 | |
| | | | | | | | | | | | | WhiteListSanitizer. This means it'll return false if called with false, however that is not a valid use case. | |||||
| * | | Stylistic improvements. Some light documentation for remove_xpaths. | Timm | 2014-06-16 | 1 | -6/+8 | |
| | | | ||||||
| * | | Simplified the removal of xpaths in remove_xpaths. Added more tests for ↵ | Timm | 2014-06-16 | 1 | -1/+1 | |
| | | | | | | | | | | | | remove_xpaths. | |||||
| * | | Fixed: added apostrophe to possessive noun. | Timm | 2014-06-16 | 1 | -1/+1 | |
| | | | ||||||
| * | | Changed: remove_xpaths called with String returns String, while called with ↵ | Timm | 2014-06-16 | 1 | -2/+2 | |
| | | | | | | | | | | | | Loofah fragment returns Loofah fragment. Added tests for this. | |||||
| * | | Removed :nodoc: from PermitScrubber. | Timm | 2014-06-16 | 1 | -1/+0 | |
| | | | ||||||
| * | | Reworked documentation for PermitScrubber and TargetScrubber. | Timm | 2014-06-16 | 1 | -2/+33 | |
| | | | ||||||
| * | | Fixed: spelling error. | Timm | 2014-06-16 | 1 | -1/+1 | |
| | | | ||||||
| * | | Initialized tags and attributes to nil. | Timm | 2014-06-16 | 1 | -0/+4 | |
| | | | ||||||
| * | | Refactored scrub to keep_node? instead of scrub_node calling it. Also added ↵ | Timm | 2014-06-16 | 1 | -6/+5 | |
| | | | | | | | | | | | | ability to stop traversing by returning STOP from scrub_node. | |||||
| * | | Changed PermitScrubber to be even more extensible. Updated TargetScrubber to ↵ | Timm | 2014-06-16 | 1 | -39/+40 | |
| | | | | | | | | | | | | be compliant. Updated documentation for PermitScrubber and TargetScrubber for clarity. | |||||
| * | | Changed PermitScrubbers documentation to list override points for ↵ | Timm | 2014-06-16 | 1 | -12/+15 | |
| | | | | | | | | | | | | subclasses. Renamed should_remove_attributes? to should_scrub_attributes?. | |||||
| * | | Already killed off LinkScrubber. Changed it instead to be TargetScrubber, ↵ | Timm | 2014-06-16 | 2 | -9/+20 | |
| | | | | | | | | | | | | which is more general, while still allowing maximum code reuse. | |||||
| * | | Added LinkScrubber to remove duplication in LinkSanitizer. As such made ↵ | Timm | 2014-06-16 | 2 | -11/+22 | |
| | | | | | | | | | | | | PermitScrubber easier to subclass. | |||||
| * | | Changed FullSanitizer sanitize to use tap method instead of temporary variable. | Timm | 2014-06-16 | 1 | -3/+3 | |
| | | | ||||||
| * | | Extracted the common xpaths to remove into XPATHS_TO_REMOVE. | Timm | 2014-06-16 | 1 | -2/+4 | |
| | | | ||||||
| * | | Refactored remove_xpaths to use duck typing and read better. | Timm | 2014-06-16 | 1 | -4/+5 | |
| | | | ||||||
| * | | Changed explanation for no duck typing of custom scrubbers. | Timm | 2014-06-16 | 1 | -1/+2 | |
| | | | ||||||
| * | | Updated documentation to tell that a custom scrubber takes precedence. | Timm | 2014-06-15 | 1 | -0/+1 | |
| | | | ||||||
| * | | Updated the documentation to reflect the scrubber option. | Timm | 2014-06-15 | 1 | -1/+22 | |
| | | | ||||||
| * | | Marked the private API as not needing code documentation. | Timm | 2014-06-15 | 2 | -0/+2 | |
| | | | ||||||
| * | | Added ability to pass a custom scrubber to sanitize. Includes test coverage. | Timm | 2014-06-15 | 1 | -1/+3 | |
| | | | ||||||
| * | | Moved requiring of Loofah from sanitizers.rb to action_view.rb. | Timm | 2014-06-15 | 1 | -1/+0 | |
| | | | ||||||
| * | | Added ActionView::Sanitizer and moved remove_xpaths to there. | Timm | 2014-06-15 | 1 | -7/+0 | |
| | | | ||||||
| * | | Added comment removal. Changed definitation of remove_xpaths to not use a ↵ | Timm | 2014-06-15 | 1 | -11/+24 | |
| | | | | | | | | | | | | splat operator. | |||||
| * | | Extracted the xpath removals into some new API that allows users to remove ↵ | Timm | 2014-06-15 | 1 | -2/+8 | |
| | | | | | | | | | | | | xpath subtrees. |