From: David Heinemeier Hansson Date: 2004-07-26T01:51:19+09:00 Subject: Re: [ANN] Rails 0.5.0: The end of vaporware! > I'm surprised that there is no easy way to deal with this issue; after > seeing all these examples with date types being automatically > displayed as a selection form etc. I would have expected Rails to take > care of properly escaping simple strings. I guess it depends on what kind of application you're building. For content-heavy applications, such as weblogs, discussion board, content management systems, etc, it's often the case that you _don't_ want the strings escaped. And even if you don't want them escaped, it's likely that you need more advanced escaping anyway. But I agree that CGI.escapeHTML is a bit rich, so I'll add some kind of shorther wrapper for that to the TextHelper in the next version. No need to wait, though. Edit vendor/actionpack/lib/action_view/helpers/text_helper.rb and add this method: def escape(string) CGI.escapeHTML(string) end If you think that's two much to type, perhaps also: alias_method :e, :escape Then you're all ready to rock with <%= e(@post.text) %> -- David Heinemeier Hansson, http://www.rubyonrails.org/ -- Web-application framework for Ruby http://www.instiki.org/ -- A No-Step-Three Wiki in Ruby http://www.basecamphq.com/ -- Web-based Project Management http://www.loudthinking.com/ -- Broadcasting Brain http://www.nextangle.com/ -- Development & Consulting Services