From: Andreas Schwarz Date: 2004-07-26T05:26:52+09:00 Subject: Re: [ANN] Rails 0.5.0: The end of vaporware! David Heinemeier Hansson wrote: >> I'm surprised that there is no easy way to deal with this issue; after >> seeing all these examples with date types being automatically >> displayed as a selection form etc. I would have expected Rails to take >> care of properly escaping simple strings. > > I guess it depends on what kind of application you're building. For > content-heavy applications, such as weblogs, discussion board, content > management systems, etc, it's often the case that you _don't_ want the > strings escaped. In every web application I have built so far there was barely a variable that needed to be displayed without escaping. Take a discussion board: you certainly want to escape the author name, email address, subject, and most of the times the text of the post. If you don't do this you get something like PhpBB where they discover a new XSS possibility every other day. Especially when there is a strict division between data and template code (like in Rails) I would expect unescaped strings to be an exception. > And even if you don't want them escaped, it's likely > that you need more advanced escaping anyway. Why? As long as you make consistent use of one charset there is no need to escape anything else than XML special characters. > But I agree that CGI.escapeHTML is a bit rich, so I'll add some kind of > shorther wrapper for that to the TextHelper in the next version. That's good. I'm looking forward to doing my first project with Rails.