From: Jamis Buck Date: 2004-07-26T02:00:46+09:00 Subject: Re: [ANN] Rails 0.5.0: The end of vaporware! Carl Youngblood wrote: > I think a better solution if you wanted something like this would be > to alter rails so it changes the variables in the @post object before > displaying them. But I'm not sure everyone would want this behavior. > > On Sun, 25 Jul 2004 22:21:54 +0900, Andreas Schwarz > wrote: > >>Maybe it would make sense to extend Eruby/Erb/whatever with another tag >>that wraps the content in CGI.escapeHTML? For example >>{%= @post.text %} >>instead of >><%= CGI.escapeHTML( @post.text ) %> >>? > > > . > Well, here's a quick hack that anyone could do in their code to make the autoescaping (and explicit non-escaping) possible: require 'erb' require 'cgi' class String NO_ESC_REGEX = /^NOESCAPE:(.*)/ def html_safe_concat( text ) if text =~ NO_ESC_REGEX concat($1) else concat(CGI.escapeHTML(text)) end end end class ERB alias :old_set_eoutvar :set_eoutvar def set_eoutvar(compiler, eoutvar='_erbout') old_set_eoutvar( compiler, eoutvar ) compiler.put_cmd = "#{eoutvar}.html_safe_concat" end end X = "NOESCAPE:" @something = "" @notme = "not me, \"please\"" erb = ERB.new "This is <%=@something%> with text, and <%=X+@notme%>" p erb.result # -> "This is <escape "me" baby> with text, and not me, \"please\"" Not perfect, obviously, but it does work. -- Jamis Buck jgb3@email.byu.edu http://www.jamisbuck.org/jamis "I use octal until I get to 8, and then I switch to decimal."