mirror of
https://github.com/rails/rails.git
synced 2022-11-09 12:12:34 -05:00
0c7ac34aed
i18n doesn't depend on active support which means it can't use our html_safe code to do its escaping when generating the spans. Rather than try to sanitize the output from i18n, just revert to our old behaviour of rescuing the error and constructing the tag ourselves. Fixes: CVE-2013-4491 |
||
---|---|---|
.. | ||
actionpack | ||
activerecord | ||
fixtures | ||
lib/controller | ||
template | ||
tmp | ||
abstract_unit.rb | ||
active_record_unit.rb |