Forum: Ruby on Rails Textile and h problems

Announcement (2017-05-07): is now read-only since I unfortunately do not have the time to support and maintain the forum any more. Please see and for other Rails- und Ruby-related community platforms.
Mike C. (Guest)
on 2009-01-12 06:21
(Received via mailing list)
I installed Redcloth into my app so that it could use Textile.
However, it seems that textilize (the function used to parse the
Textile stuff) and h aren't compatible. If I do <%= textilize h
@mymessage %> it doesn't work. If I take out the h it works but then I
leave myself open to XSS. Is there a way to get around this?
Essentially I was trying to allow users to do basic HTML functions and
weed out javascript.
Ryan B. (Guest)
on 2009-01-12 06:59
(Received via mailing list)
Ryan B.
Mike C. (Guest)
on 2009-01-12 07:36
(Received via mailing list)
That doesn't work since textilize parses it into html and then h will,
of course, take those away. Anyways I found a solution to my problem.
It seems that you shouldn't use textilize but just use
(message, [:filter_html])
This topic is locked and can not be replied to.