开发者

Rails render raw html but escape javascript?

So I have some user generated content areas of my site. I want 开发者_开发问答them to be able to use html for markup purposes, but I don't want them to be able to execute any arbitrary javascript.

From my understanding raw() will just output everything, html, javascript, and all right into the webpage.

Is there a method that will allow raw rendering of html but not allow rendering of javascript?


Have a look at sanitize.

0

上一篇:

下一篇:

精彩评论

暂无评论...
验证码 换一张
取 消

最新问答

问答排行榜