Alex Rivera | Logout

Escaping HTML in Rails

Asked 2009-03-30T19:36:51.830
26

What is the recommended way to escape HTML to prevent XSS vulnerabilities in Rails apps?

Should you allow the user to put any text into the database but escape it when displaying it? Should you add before_save filters to escape the input?

Edit
Report

1 Answer

0

I've just released a plugin called ActsAsSanitiled using the Sanitize gem which can guarantee well-formedness as well being very configurable to what kind of HTML is allowed, all without munging user input or requiring anything to be remembered at the template level.

answered 2009-10-15T07:24:13.913

Your Answer