> Have a look at TextHelper#sanitize and go from there. > http://ha.ckers.org/xss.html has a good list of things to guard for. > It would be cool to turn that site into a test case and work until we > pass 'em all.
Yep, that's exactly what I had in mind too =) _______________________________________________ Rails-core mailing list Rails-core@lists.rubyonrails.org http://lists.rubyonrails.org/mailman/listinfo/rails-core