14
Right now we're using the sanitize gem: https://github.com/rgrove/sanitize
Problem is if you enter "hello & world" sanitize is saving that in the DB as:
hello & world
How can you whitelist the & . We want sanitize to remove all possible malicious html and JS/script tags. but we're ok allowing the ampersand.
Ideas? Thanks