Uh oh,
I just got the in_place_editor_field almost working and I realized that
I was no longer escaping all user inputted text. I''ve caught the
general drift that evil people will eat my database alive if I display
nefarious input they could put in?
Is that a good reason not to use that feature?
I''m going to need to find some good bullet proof filters to put user
inputted data through regardless I suppose?
--
Posted via http://www.ruby-forum.com/.
--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups
"Ruby on Rails: Talk" group.
To post to this group, send email to
rubyonrails-talk-/JYPxA39Uh5TLH3MbocFFw@public.gmane.org
To unsubscribe from this group, send email to
rubyonrails-talk-unsubscribe-/JYPxA39Uh5TLH3MbocFFw@public.gmane.org
For more options, visit this group at
http://groups.google.com/group/rubyonrails-talk?hl=en
-~----------~----~----~----~------~----~------~--~---