1
0
Fork 0
mirror of https://github.com/rails/rails.git synced 2022-11-09 12:12:34 -05:00
rails--rails/actionview/lib/action_view
Rafael Mendonça França 33cb47ee48 Use the reference for the mime type to get the format
Before we were calling to_sym in the mime type, even when it is unknown
what can cause denial of service since symbols are not removed by the
garbage collector.

Fixes: CVE-2014-0082
2014-02-18 16:12:51 -03:00
..
helpers Merge branch '4-1-0-beta2' 2014-02-18 16:00:47 -03:00
locale
renderer Introduce render :html for render HTML string 2014-02-18 12:08:36 -05:00
tasks Adds template dependencies rake task from cache_digests gem. 2013-09-26 21:19:19 +02:00
template Use the reference for the mime type to get the format 2014-02-18 16:12:51 -03:00
testing Action Pack Variants 2013-12-04 00:13:16 +01:00
vendor Merge branch 'master' of github.com:lifo/docrails 2013-12-20 00:10:30 +05:30
base.rb Rails config for raise on missing translations 2014-01-27 08:03:46 -02:00
buffers.rb
context.rb
dependency_tracker.rb Avoid scanning multiple render calls as a single match. 2014-01-09 20:37:00 -02:00
digestor.rb add a new local variable to track if digests are being stored, to ensure the cleanup works correctly 2013-10-17 09:00:37 +13:00
flows.rb Comment typo 2013-06-25 14:34:51 -04:00
helpers.rb Make ActionView::Tags loading tread safe 2013-12-02 20:27:50 -02:00
layouts.rb Introduce render :html for render HTML string 2014-02-18 12:08:36 -05:00
log_subscriber.rb Drop one more string allocation 2013-11-09 18:28:32 -02:00
lookup_context.rb just require the template resolver 2014-01-31 12:05:50 -08:00
model_naming.rb
path_set.rb
railtie.rb Remove the explicit order set for the initializer 2013-12-05 16:37:10 -02:00
record_identifier.rb
rendering.rb Add #no_content_type attribute to AD::Response 2014-02-18 12:11:41 -05:00
routing_url_for.rb Take Hash with options inside Array in #url_for 2013-11-15 15:50:42 +04:00
template.rb Introduce render :html for render HTML string 2014-02-18 12:08:36 -05:00
test_case.rb
version.rb Preparing for 4.1.0.beta2 release 2014-02-18 15:45:20 -03:00
view_paths.rb Revert "Require only path_set && lookup_context instead of whole base" 2013-08-25 11:39:08 +02:00