There has been a discussion about whether to untaint or not. A string becomes tainted in Ruby when it comes from an external source, for example. The standard Ruby method untaint marks it as untainted. Plugins such as SafeErb do not allow the programmer to output tainted strings (in Erb) in order to protect the […]
Entries from February 2008
The Tainted Edition
February 13th, 2008 · 4 Comments
Tags: Rails · Uncategorized · XSS and Rails





