Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix HTML escaping problems #53

Merged
merged 3 commits into from
Feb 6, 2021

Conversation

daniel-rikowski
Copy link

This fixes #50 resp. awesome-print/awesome_print#199

Also this prevents the ActiveRecord formatters from emitting unescaped #<ClassName#object_id> or Class < Superclass strings, which couldn't be catched by the caller even with manual escaping.

Existing code using workarounds like <%= raw ap ... %> or <%= (ap ...).html_safe %> will continue to work.

@paddor
Copy link
Contributor

paddor commented Oct 1, 2020

Thanks for the PR. I haven't touched Rails in forever. Can this be verified in a test case?

@HarlemSquirrel
Copy link
Member

@daniel-rikowski Do you have some time to resolve the conflicts? Thank you!

@daniel-rikowski
Copy link
Author

I rebased my pull request, but now tests are failing. It looks like 25352d2 added an explicit test to enforce that the returned HTML is not marked as safe. It looks like it declares #50 to be the intended behaviour.

I'm not sure what to do here...

@HarlemSquirrel
Copy link
Member

I wrote a test to verify how it works today. Could you update the test to verify this change?
Thank you!

@daniel-rikowski
Copy link
Author

Oh, sorry, I didn't notice #65 🙈

I updated the test and added a new one for the ActiveRecord subclass bug, i.e. the < in ChildModel < ParentModel wasn't escaped as &lt; when using html: true.

Copy link
Member

@HarlemSquirrel HarlemSquirrel left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

ActionView ap displays as string instead of HTML
3 participants