From: Zev Blut Date: 2005-05-19T17:18:54+09:00 Subject: Re: [ ruby-Bugs-1930 ] CGI::escapeHTML escapes the ampersand in an existing escape command Thu, 19 May 2005 13:09:45 +0900, nobuyoshi nakada wrote: > Hi, > > At Thu, 19 May 2005 11:51:47 +0900, > noreply@rubyforge.org wrote in [ruby-core:05039]: >> Initial Comment: >> CGI::escapeHTML will escape all "&" found in a text passed to it. This >> means that if the text contains an escape command that uses the & >> escape notation, like €, then it will break the notation. > > It is exactly expected behavior. OK. It would be nice if that was in the documentation somewhere, so that other people do not make the same mistake. > The way to let escapeHTML not to escape a particular ampersand is > another story. I can see the need for the current behavior and of course I have the need for the changed behavior. Two techniques for providing a preserving escape come to my mind. One would be to add an optional boolean argument that when true will keep escape commands, the default value is false and thus current usage will not change. Another is to add another method that implements the patch provided in the report. A few possible method names are : loose_escape_html escape_and_preserve_html minimal_escape_html partial_escape_html Any other ideas? Cheers, Zev Blut BTW, it is there a way for the bug report interface to get all of the ruby-core email comments about a bug added to the comment history?