From 5218b43df4f519ac32c7204011fb2910b24b4a6b Mon Sep 17 00:00:00 2001 From: Matchu Date: Sun, 8 Apr 2012 14:53:26 -0500 Subject: [PATCH] fix petpage export item name filtering The "Abominable Snowball Winter Onesie" can get blocked for including the string " On". So, we meant to filter that to " On" so that the filter wouldn't return that false positive on an XSS attempt, but were accidentally filtering it to " o<b></b&;gtn". Fixed :) --- app/helpers/closet_hangers_helper.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/helpers/closet_hangers_helper.rb b/app/helpers/closet_hangers_helper.rb index dbab3425..d389cac0 100644 --- a/app/helpers/closet_hangers_helper.rb +++ b/app/helpers/closet_hangers_helper.rb @@ -77,7 +77,7 @@ module ClosetHangersHelper end def petpage_item_name(item) - item.name.gsub(/ on/i, ' on') + item.name.gsub(/ On/i, ' On').html_safe end PETPAGE_IMAGE_URL_BLACKLIST = %w(window. ondrop)