Rails ã®ã¢ããªã±ã¼ã·ã§ã³ã§ DB ã HTTP ãªã¯ã¨ã¹ãããåã£ã¦ããæååã rhtml ã§åºåããã¨ãã« h ã¡ã½ãããªã©ã§ã¨ã¹ã±ã¼ãããªãã¨ã¨ã©ã¼ãåºãã¨ãããã©ã°ã¤ã³ãä½ã£ã¦ã¿ã¾ãããå®è£ æ¹æ³ã¨ãã¦ã¯ Ruby ã® Object#tainted? ã¡ã½ããã使ã£ã¦æååãã¨ã¹ã±ã¼ãå¦çãééãã¦ãããã©ããå¤å®ããã¨ããåç´ãªãã®ã§ããèªåçã«ã¨ã¹ã±ã¼ãå¦çãå ¥ããããã§ã¯ãªãã®ã§æ¢åã®ã¢ããªã±ã¼ã·ã§ã³ã¨äºææ§ãä¿ã¡ã¤ã¤ãXSS ãªã©ãå¼ãããã Script Insertion ã許ãã¦ãã¾ãå¯è½æ§ãããªãä¸ããããã¨æãã¾ããREADME: http://wiki.rubyonrails.org/rails/pages/Safe+ERBãã¦ã³ãã¼ã: http://www.kbmj.com/users/shinya/rails/safe_erb-0.1.zipRuby
{{#tags}}- {{label}}
{{/tags}}