rails3以éã®WEBã¢ããªã±ã¼ã·ã§ã³ã«ãããã¡ãªXSS - hanagemanã®æ¥è¨ã§ã¯ãªã ãã®è¨äºãèªãã§ãã¡ããã©æè¿ä½¿ã£ã¦ããGoogle Closure Templatesãããæãã ã£ãã®ã§ç´¹ä»ãã¾ãã ã³ã³ããã¹ããç°ãªã/éãªããã¤ã³ãã§ã®ã¨ã¹ã±ã¼ãåé¡ æè¿ã®ã»ã¨ãã©ã®ãã³ãã¬ã¼ãã¨ã³ã¸ã³ã§ã¯ãå¤æ°åãè¾¼ã¿ãããã©ã«ãã§HTMLã¨ã¹ã±ã¼ããã¦ããã¾ããããå è¨äºã§ææããã¦ããããã«ãããã§ã¯æ£ãããªãã±ã¼ã¹ãããã¾ããHTML PCDATA以å¤ã®ã³ã³ããã¹ãã§æååãçæããããè¤æ°ã®ã³ã³ããã¹ããéãªã£ã¦ããç®æã§ãã 極端ãªä¾ã¨ãã¦ã¯ãããªæãã§ãã <a href="{$x1}" onclick="alert('{$x2}')">{$x3}</a> <script> var x = '{$x4}'; var y = {$x5}; </script> <styl
{{#tags}}- {{label}}
{{/tags}}