Stay safe while using html_safe in Rails
http://product.reverb.com/2015/08/29/stay-safe-while-using-html_safe-in-rails/
Don’t accidentally introduce XSS vulnerabilities to your app when using html_safe. Learn what ActiveSupport::SafeBuffer is and how you should use it.
Post a comment