From 5690cf4d4e05eafdfd2e270bbdf1a925114d0f76 Mon Sep 17 00:00:00 2001 From: erdgeist Date: Sun, 9 Aug 2026 23:31:35 +0200 Subject: Escape feed content with Builder rather than by hand Builder escapes by default; the three feed templates no longer call CGI.escapeHTML. This fixes two sites that never escaped at all: the tag feed's externally supplied :tag segment, interpolated into its title, self link and id, and dc:creator in the RDF template. Subscribers see one difference: quotes and apostrophes arrive raw, which is valid in element text. config/initializers/xmlparser.rb, which redefined Builder::XmlBase#_escape as the identity function, is gone. XML::Node#replace_with went with it, no callers. --- app/views/rss/updates.rdf.builder | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'app/views/rss/updates.rdf.builder') diff --git a/app/views/rss/updates.rdf.builder b/app/views/rss/updates.rdf.builder index b4fecdb0..699e9c87 100644 --- a/app/views/rss/updates.rdf.builder +++ b/app/views/rss/updates.rdf.builder @@ -17,9 +17,9 @@ xml.tag!("rdf:RDF", "xmlns:rdf" => "http://www.w3.org/1999/02/22-rdf-syntax-ns#" @items.each do |item| xml.item("rdf:about" => content_url(:page_path => item.node.unique_path)) do - xml.title(CGI.escapeHTML(item.title.to_s)) + xml.title(item.title.to_s) xml.link(content_url(:page_path => item.node.unique_path)) - xml.description(CGI.escapeHTML(item.abstract.to_s)) + xml.description(item.abstract.to_s) xml.tag!("dc:creator", (item.user ? item.user.login : "CCC")) xml.tag!("dc:date", item.published_at.xmlschema) end -- cgit v1.3