adds text_with_links helper and use that in any comment.body in views, adds test to check for malicious injections in comment body

This commit is contained in:
David Gil
2015-09-10 18:28:10 +02:00
parent f6246bf290
commit 31cf51f07a
11 changed files with 35 additions and 19 deletions

View File

@@ -0,0 +1,9 @@
module TextWithLinksHelper
def text_with_links(text)
return unless text
sanitized = sanitize text, tags: %w(a), attributes: %w(href)
Rinku.auto_link(sanitized, :all, 'target="_blank" rel="nofollow"').html_safe
end
end