On 2/12/06, Nathaniel S. H. Brown <[EMAIL PROTECTED]> wrote:
> All of those helper functions would obviously need to be changed so that
> they work with the default <%=h methods. The <%= tag could be smart enough
> to realize what it is parsing, and if it's a helper method, to skip it.
>
> It's an abstract idea. If it's worth investigating, we can look at how to
> implement it, on a more specific level. Especially what implications it has,
> as you have mentioned.
>
> As far as I am concerned, these are minor details which can be ironed out
> with a bit of creativity.

I don't actually think that's possible.    Whatever new output link_to
returned, would just be the new target for XSS guys.


--
Cheers

Koz
_______________________________________________
Rails-core mailing list
Rails-core@lists.rubyonrails.org
http://lists.rubyonrails.org/mailman/listinfo/rails-core

Reply via email to