Avoid double-escaping diary entry titles
The XML builder takes care of the escaping, and adding h() lead to double-escaped titles in the RSS feed.
This commit is contained in:
parent
f7b4793c50
commit
4a9aa0a12e
2 changed files with 8 additions and 1 deletions
|
@ -563,6 +563,13 @@ class DiaryEntryControllerTest < ActionController::TestCase
|
|||
assert_response :not_found, "Should not be able to get a deleted users diary RSS"
|
||||
end
|
||||
|
||||
def test_rss_character_escaping
|
||||
create(:diary_entry, :title => "<script>")
|
||||
get :rss, :format => :rss
|
||||
|
||||
assert_match "<title><script></title>", response.body
|
||||
end
|
||||
|
||||
def test_view
|
||||
# Try a normal entry that should work
|
||||
diary_entry = create(:diary_entry, :user => users(:normal_user))
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue