From 7fd475273a4a09e7a10835cca94e6b0dc396c719 Mon Sep 17 00:00:00 2001 From: Adrien Siami Date: Wed, 21 Aug 2013 15:29:12 +0200 Subject: Escape the message of an exception in debug_exceptions to avoid bad rendering --- .../lib/action_dispatch/middleware/templates/rescues/diagnostics.erb | 2 +- .../action_dispatch/middleware/templates/rescues/missing_template.erb | 2 +- .../lib/action_dispatch/middleware/templates/rescues/routing_error.erb | 2 +- .../lib/action_dispatch/middleware/templates/rescues/template_error.erb | 2 +- .../lib/action_dispatch/middleware/templates/rescues/unknown_action.erb | 2 +- 5 files changed, 5 insertions(+), 5 deletions(-) (limited to 'actionpack/lib/action_dispatch/middleware/templates/rescues') diff --git a/actionpack/lib/action_dispatch/middleware/templates/rescues/diagnostics.erb b/actionpack/lib/action_dispatch/middleware/templates/rescues/diagnostics.erb index 57a2940802..f154021ae6 100644 --- a/actionpack/lib/action_dispatch/middleware/templates/rescues/diagnostics.erb +++ b/actionpack/lib/action_dispatch/middleware/templates/rescues/diagnostics.erb @@ -8,7 +8,7 @@
-

<%= @exception.message %>

+

<%= h @exception.message %>

<%= render template: "rescues/_source" %> <%= render template: "rescues/_trace" %> diff --git a/actionpack/lib/action_dispatch/middleware/templates/rescues/missing_template.erb b/actionpack/lib/action_dispatch/middleware/templates/rescues/missing_template.erb index ca14215946..5c016e544e 100644 --- a/actionpack/lib/action_dispatch/middleware/templates/rescues/missing_template.erb +++ b/actionpack/lib/action_dispatch/middleware/templates/rescues/missing_template.erb @@ -3,5 +3,5 @@
-

<%= @exception.message %>

+

<%= h @exception.message %>

diff --git a/actionpack/lib/action_dispatch/middleware/templates/rescues/routing_error.erb b/actionpack/lib/action_dispatch/middleware/templates/rescues/routing_error.erb index cd3daff065..7e9cedb95e 100644 --- a/actionpack/lib/action_dispatch/middleware/templates/rescues/routing_error.erb +++ b/actionpack/lib/action_dispatch/middleware/templates/rescues/routing_error.erb @@ -2,7 +2,7 @@

Routing Error

-

<%= @exception.message %>

+

<%= h @exception.message %>

<% unless @exception.failures.empty? %>

Failure reasons:

diff --git a/actionpack/lib/action_dispatch/middleware/templates/rescues/template_error.erb b/actionpack/lib/action_dispatch/middleware/templates/rescues/template_error.erb index 31f46ee340..027a0f5b3e 100644 --- a/actionpack/lib/action_dispatch/middleware/templates/rescues/template_error.erb +++ b/actionpack/lib/action_dispatch/middleware/templates/rescues/template_error.erb @@ -10,7 +10,7 @@

Showing <%= @exception.file_name %> where line #<%= @exception.line_number %> raised:

-
<%= @exception.message %>
+
<%= h @exception.message %>
diff --git a/actionpack/lib/action_dispatch/middleware/templates/rescues/unknown_action.erb b/actionpack/lib/action_dispatch/middleware/templates/rescues/unknown_action.erb index c1fbf67eed..259fb2bb3b 100644 --- a/actionpack/lib/action_dispatch/middleware/templates/rescues/unknown_action.erb +++ b/actionpack/lib/action_dispatch/middleware/templates/rescues/unknown_action.erb @@ -2,5 +2,5 @@

Unknown action

-

<%= @exception.message %>

+

<%= h @exception.message %>

-- cgit v1.2.3