开发者

Rails render raw html but escape javascript?

开发者 https://www.devze.com 2023-03-27 14:07 出处:网络
So I have some user generated content areas of my site. I want 开发者_开发问答them to be able to use html for markup purposes, but I don\'t want them to be able to execute any arbitrary javascript.

So I have some user generated content areas of my site. I want 开发者_开发问答them to be able to use html for markup purposes, but I don't want them to be able to execute any arbitrary javascript.

From my understanding raw() will just output everything, html, javascript, and all right into the webpage.

Is there a method that will allow raw rendering of html but not allow rendering of javascript?


Have a look at sanitize.

0

精彩评论

暂无评论...
验证码 换一张
取 消

关注公众号