From: SpringFlowers AutumnMoon Date: 2008-09-28T04:28:45+09:00 Subject: h() or html_escape() not escape the single quote... risky? so h() is an alias for html_escape() and they convert the following 4 characters < > & " into < > & " the single quote is not converted... I just wonder sometimes we happen to write code such as and it can cause an cross-site scripting (XSS) attack? we usually use double quote but sometimes we use single quote like somebody can write puts "" (sorry i have used PHP for quite some time and so by Ruby is rusty...) -- Posted via http://www.ruby-forum.com/.