From: m4dc4p Date: 2006-01-26T07:08:12+09:00 Subject: Re: Ruby, Web Apps and Cross Site Scripting What about something where you subclass any strings coming out of 'self[]'? This is some real quick and dirty pseudo code but you could do: class ActiveRecord::Base def [](value) v = super(value) if (! v.nil?) && v.is_a?(String) class << v def to_s CGI::escapeHTML(super) end def unsafe_to_s superclass.to_s # Not sure if this is valid- but basically get the raw string end end end end This way, any time a string comes out of an ActiveRecord column, you override it to automatically product safe HTML. If you don't want that behavior, you just call unsafe_to_s. Kevin Olbrich wrote: > Good stuff, I posted a comment on the subject. The gist of it being > that is probably better make escaping the default action on all columns > and set up a mechanism to specifically over-ride the escaping to get the > real value. (yeah, you could probably get smart and not bother to > escape non-text columns). > > _Kevin > > -- > Posted via http://www.ruby-forum.com/.