form_tag_helper.rb 24.3 KB
Newer Older
1
require 'cgi'
2
require 'action_view/helpers/tag_helper'
3
require 'active_support/core_ext/object/returning'
4
require 'active_support/core_ext/object/blank'
5 6 7

module ActionView
  module Helpers
P
Pratik Naik 已提交
8
    # Provides a number of methods for creating form tags that doesn't rely on an Active Record object assigned to the template like
9
    # FormHelper does. Instead, you provide the names and values manually.
10
    #
11
    # NOTE: The HTML options <tt>disabled</tt>, <tt>readonly</tt>, and <tt>multiple</tt> can all be treated as booleans. So specifying
12
    # <tt>:disabled => true</tt> will give <tt>disabled="disabled"</tt>.
13
    module FormTagHelper
W
wycats 已提交
14 15 16 17 18
      extend ActiveSupport::Concern

      include UrlHelper
      include TextHelper

19
      # Starts a form tag that points the action to an url configured with <tt>url_for_options</tt> just like
20 21
      # ActionController::Base#url_for. The method for the form defaults to POST.
      #
22
      # ==== Options
23
      # * <tt>:multipart</tt> - If set to true, the enctype is set to "multipart/form-data".
P
Pratik Naik 已提交
24 25 26
      # * <tt>:method</tt> - The method to use when submitting the form, usually either "get" or "post".
      #   If "put", "delete", or another verb is used, a hidden input with name <tt>_method</tt>
      #   is added to simulate the verb over post.
27
      # * A list of parameters to feed to the URL the form will be posted to.
S
Stefan Penner 已提交
28 29
      # * <tt>:remote</tt> - If set to true, will allow the Unobtrusive JavaScript drivers to control the 
      #   submit behaviour. By default this behaviour is an ajax submit.
30 31
      #
      # ==== Examples
32
      #   form_tag('/posts')
33 34
      #   # => <form action="/posts" method="post">
      #
35
      #   form_tag('/posts/1', :method => :put)
36 37
      #   # => <form action="/posts/1" method="put">
      #
38
      #   form_tag('/upload', :multipart => true)
39
      #   # => <form action="/upload" method="post" enctype="multipart/form-data">
40
      #
41
      #   <%= form_tag('/posts')do -%>
42 43 44
      #     <div><%= submit_tag 'Save' %></div>
      #   <% end -%>
      #   # => <form action="/posts" method="post"><div><input type="submit" name="submit" value="Save" /></div></form>
S
Stefan Penner 已提交
45
      # 
46
      #  <%= form_tag('/posts', :remote => true) %>
S
Stefan Penner 已提交
47 48
      #   # => <form action="/posts" method="post" data-remote="true">
      #   
49
      def form_tag(url_for_options = {}, options = {}, *parameters_for_url, &block)
50
        html_options = html_options_for_form(url_for_options, options, *parameters_for_url)
51
        if block_given?
52
          form_tag_in_block(html_options, &block)
53
        else
54
          form_tag_html(html_options)
55
        end
56 57
      end

58 59 60 61
      # Creates a dropdown selection box, or if the <tt>:multiple</tt> option is set to true, a multiple
      # choice selection box.
      #
      # Helpers::FormOptions can be used to create common select boxes such as countries, time zones, or
62 63 64 65 66 67
      # associated records. <tt>option_tags</tt> is a string containing the option tags for the select box.
      #
      # ==== Options
      # * <tt>:multiple</tt> - If set to true the selection will allow multiple choices.
      # * <tt>:disabled</tt> - If set to true, the user will not be able to use this input.
      # * Any other key creates standard HTML attributes for the tag.
68
      #
69
      # ==== Examples
P
Pratik Naik 已提交
70 71
      #   select_tag "people", options_from_collection_for_select(@people, "name", "id")
      #   # <select id="people" name="people"><option value="1">David</option></select>
72
      #
73
      #   select_tag "people", "<option>David</option>"
74
      #   # => <select id="people" name="people"><option>David</option></select>
75
      #
76 77 78 79 80
      #   select_tag "count", "<option>1</option><option>2</option><option>3</option><option>4</option>"
      #   # => <select id="count" name="count"><option>1</option><option>2</option>
      #   #    <option>3</option><option>4</option></select>
      #
      #   select_tag "colors", "<option>Red</option><option>Green</option><option>Blue</option>", :multiple => true
81
      #   # => <select id="colors" multiple="multiple" name="colors[]"><option>Red</option>
82 83 84 85 86 87 88
      #   #    <option>Green</option><option>Blue</option></select>
      #
      #   select_tag "locations", "<option>Home</option><option selected="selected">Work</option><option>Out</option>"
      #   # => <select id="locations" name="locations"><option>Home</option><option selected='selected'>Work</option>
      #   #    <option>Out</option></select>
      #
      #   select_tag "access", "<option>Read</option><option>Write</option>", :multiple => true, :class => 'form_input'
89
      #   # => <select class="form_input" id="access" multiple="multiple" name="access[]"><option>Read</option>
90 91 92 93 94
      #   #    <option>Write</option></select>
      #
      #   select_tag "destination", "<option>NYC</option><option>Paris</option><option>Rome</option>", :disabled => true
      #   # => <select disabled="disabled" id="destination" name="destination"><option>NYC</option>
      #   #    <option>Paris</option><option>Rome</option></select>
95
      def select_tag(name, option_tags = nil, options = {})
96 97 98 99
        if Array === option_tags
          ActiveSupport::Deprecation.warn 'Passing an array of option_tags to select_tag implicitly joins them without marking them as HTML-safe. Pass option_tags.join.html_safe instead.', caller
        end

100
        html_name = (options[:multiple] == true && !name.to_s.ends_with?("[]")) ? "#{name}[]" : name
101 102
        if blank = options.delete(:include_blank)
          if blank.kind_of?(String)
103
            option_tags = "<option value=\"\">#{blank}</option>".html_safe + option_tags
104
          else
105
            option_tags = "<option value=\"\"></option>".html_safe + option_tags
106 107
          end
        end
108
        content_tag :select, option_tags, { "name" => html_name, "id" => sanitize_to_id(name) }.update(options.stringify_keys)
109 110
      end

111 112
      # Creates a standard text field; use these text fields to input smaller chunks of text like a username
      # or a search query.
113
      #
114
      # ==== Options
115 116 117
      # * <tt>:disabled</tt> - If set to true, the user will not be able to use this input.
      # * <tt>:size</tt> - The number of visible characters that will fit in the input.
      # * <tt>:maxlength</tt> - The maximum number of characters that the browser will allow the user to enter.
118
      # * Any other key creates standard HTML attributes for the tag.
119
      #
120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140
      # ==== Examples
      #   text_field_tag 'name'
      #   # => <input id="name" name="name" type="text" />
      #
      #   text_field_tag 'query', 'Enter your search query here'
      #   # => <input id="query" name="query" type="text" value="Enter your search query here" />
      #
      #   text_field_tag 'request', nil, :class => 'special_input'
      #   # => <input class="special_input" id="request" name="request" type="text" />
      #
      #   text_field_tag 'address', '', :size => 75
      #   # => <input id="address" name="address" size="75" type="text" value="" />
      #
      #   text_field_tag 'zip', nil, :maxlength => 5
      #   # => <input id="zip" maxlength="5" name="zip" type="text" />
      #
      #   text_field_tag 'payment_amount', '$0.00', :disabled => true
      #   # => <input disabled="disabled" id="payment_amount" name="payment_amount" type="text" value="$0.00" />
      #
      #   text_field_tag 'ip', '0.0.0.0', :maxlength => 15, :size => 20, :class => "ip-input"
      #   # => <input class="ip-input" id="ip" maxlength="15" name="ip" size="20" type="text" value="0.0.0.0" />
141
      def text_field_tag(name, value = nil, options = {})
142
        tag :input, { "type" => "text", "name" => name, "id" => sanitize_to_id(name), "value" => value }.update(options.stringify_keys)
143 144 145 146
      end

      # Creates a label field
      #
147
      # ==== Options
148 149 150 151 152 153 154 155 156 157 158 159
      # * Creates standard HTML attributes for the tag.
      #
      # ==== Examples
      #   label_tag 'name'
      #   # => <label for="name">Name</label>
      #
      #   label_tag 'name', 'Your name'
      #   # => <label for="name">Your Name</label>
      #
      #   label_tag 'name', nil, :class => 'small_label'
      #   # => <label for="name" class="small_label">Name</label>
      def label_tag(name, text = nil, options = {})
160
        content_tag :label, text || name.to_s.humanize, { "for" => sanitize_to_id(name) }.update(options.stringify_keys)
161 162
      end

163 164 165 166 167 168 169 170 171
      # Creates a hidden form input field used to transmit data that would be lost due to HTTP's statelessness or
      # data that should be hidden from the user.
      #
      # ==== Options
      # * Creates standard HTML attributes for the tag.
      #
      # ==== Examples
      #   hidden_field_tag 'tags_list'
      #   # => <input id="tags_list" name="tags_list" type="hidden" />
172
      #
173 174 175 176
      #   hidden_field_tag 'token', 'VUBJKB23UIVI1UU1VOBVI@'
      #   # => <input id="token" name="token" type="hidden" value="VUBJKB23UIVI1UU1VOBVI@" />
      #
      #   hidden_field_tag 'collected_input', '', :onchange => "alert('Input collected!')"
177
      #   # => <input id="collected_input" name="collected_input" onchange="alert('Input collected!')"
178
      #   #    type="hidden" value="" />
179
      def hidden_field_tag(name, value = nil, options = {})
180
        text_field_tag(name, value, options.stringify_keys.update("type" => "hidden"))
181 182
      end

183
      # Creates a file upload field.  If you are using file uploads then you will also need
184
      # to set the multipart option for the form tag:
185
      #
P
Pratik Naik 已提交
186
      #   <% form_tag '/upload', :multipart => true do %>
187 188
      #     <label for="file">File to Upload</label> <%= file_field_tag "file" %>
      #     <%= submit_tag %>
P
Pratik Naik 已提交
189
      #   <% end %>
190
      #
191
      # The specified URL will then be passed a File object containing the selected file, or if the field
192
      # was left blank, a StringIO object.
193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211
      #
      # ==== Options
      # * Creates standard HTML attributes for the tag.
      # * <tt>:disabled</tt> - If set to true, the user will not be able to use this input.
      #
      # ==== Examples
      #   file_field_tag 'attachment'
      #   # => <input id="attachment" name="attachment" type="file" />
      #
      #   file_field_tag 'avatar', :class => 'profile-input'
      #   # => <input class="profile-input" id="avatar" name="avatar" type="file" />
      #
      #   file_field_tag 'picture', :disabled => true
      #   # => <input disabled="disabled" id="picture" name="picture" type="file" />
      #
      #   file_field_tag 'resume', :value => '~/resume.doc'
      #   # => <input id="resume" name="resume" type="file" value="~/resume.doc" />
      #
      #   file_field_tag 'user_pic', :accept => 'image/png,image/gif,image/jpeg'
212
      #   # => <input accept="image/png,image/gif,image/jpeg" id="user_pic" name="user_pic" type="file" />
213 214 215
      #
      #   file_field_tag 'file', :accept => 'text/html', :class => 'upload', :value => 'index.html'
      #   # => <input accept="text/html" class="upload" id="file" name="file" type="file" value="index.html" />
216
      def file_field_tag(name, options = {})
217
        text_field_tag(name, nil, options.update("type" => "file"))
218 219
      end

220
      # Creates a password field, a masked text field that will hide the users input behind a mask character.
221
      #
222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248
      # ==== Options
      # * <tt>:disabled</tt> - If set to true, the user will not be able to use this input.
      # * <tt>:size</tt> - The number of visible characters that will fit in the input.
      # * <tt>:maxlength</tt> - The maximum number of characters that the browser will allow the user to enter.
      # * Any other key creates standard HTML attributes for the tag.
      #
      # ==== Examples
      #   password_field_tag 'pass'
      #   # => <input id="pass" name="pass" type="password" />
      #
      #   password_field_tag 'secret', 'Your secret here'
      #   # => <input id="secret" name="secret" type="password" value="Your secret here" />
      #
      #   password_field_tag 'masked', nil, :class => 'masked_input_field'
      #   # => <input class="masked_input_field" id="masked" name="masked" type="password" />
      #
      #   password_field_tag 'token', '', :size => 15
      #   # => <input id="token" name="token" size="15" type="password" value="" />
      #
      #   password_field_tag 'key', nil, :maxlength => 16
      #   # => <input id="key" maxlength="16" name="key" type="password" />
      #
      #   password_field_tag 'confirm_pass', nil, :disabled => true
      #   # => <input disabled="disabled" id="confirm_pass" name="confirm_pass" type="password" />
      #
      #   password_field_tag 'pin', '1234', :maxlength => 4, :size => 6, :class => "pin-input"
      #   # => <input class="pin-input" id="pin" maxlength="4" name="pin" size="6" type="password" value="1234" />
249
      def password_field_tag(name = "password", value = nil, options = {})
250
        text_field_tag(name, value, options.update("type" => "password"))
251 252
      end

253 254 255
      # Creates a text input area; use a textarea for longer text inputs such as blog posts or descriptions.
      #
      # ==== Options
256
      # * <tt>:size</tt> - A string specifying the dimensions (columns by rows) of the textarea (e.g., "25x10").
257 258 259
      # * <tt>:rows</tt> - Specify the number of rows in the textarea
      # * <tt>:cols</tt> - Specify the number of columns in the textarea
      # * <tt>:disabled</tt> - If set to true, the user will not be able to use this input.
260 261
      # * <tt>:escape</tt> - By default, the contents of the text input are HTML escaped.
      #   If you need unescaped contents, set this to false.
262 263 264 265 266 267 268 269
      # * Any other key creates standard HTML attributes for the tag.
      #
      # ==== Examples
      #   text_area_tag 'post'
      #   # => <textarea id="post" name="post"></textarea>
      #
      #   text_area_tag 'bio', @user.bio
      #   # => <textarea id="bio" name="bio">This is my biography.</textarea>
270
      #
271 272 273 274 275 276 277 278 279 280 281
      #   text_area_tag 'body', nil, :rows => 10, :cols => 25
      #   # => <textarea cols="25" id="body" name="body" rows="10"></textarea>
      #
      #   text_area_tag 'body', nil, :size => "25x10"
      #   # => <textarea name="body" id="body" cols="25" rows="10"></textarea>
      #
      #   text_area_tag 'description', "Description goes here.", :disabled => true
      #   # => <textarea disabled="disabled" id="description" name="description">Description goes here.</textarea>
      #
      #   text_area_tag 'comment', nil, :class => 'comment_input'
      #   # => <textarea class="comment_input" id="comment" name="comment"></textarea>
282
      def text_area_tag(name, content = nil, options = {})
283 284 285
        options.stringify_keys!

        if size = options.delete("size")
286
          options["cols"], options["rows"] = size.split("x") if size.respond_to?(:split)
287
        end
288

289 290 291
        escape = options.key?("escape") ? options.delete("escape") : true
        content = html_escape(content) if escape

292
        content_tag :textarea, content.html_safe, { "name" => name, "id" => sanitize_to_id(name) }.update(options)
293 294
      end

295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315
      # Creates a check box form input tag.
      #
      # ==== Options
      # * <tt>:disabled</tt> - If set to true, the user will not be able to use this input.
      # * Any other key creates standard HTML options for the tag.
      #
      # ==== Examples
      #   check_box_tag 'accept'
      #   # => <input id="accept" name="accept" type="checkbox" value="1" />
      #
      #   check_box_tag 'rock', 'rock music'
      #   # => <input id="rock" name="rock" type="checkbox" value="rock music" />
      #
      #   check_box_tag 'receive_email', 'yes', true
      #   # => <input checked="checked" id="receive_email" name="receive_email" type="checkbox" value="yes" />
      #
      #   check_box_tag 'tos', 'yes', false, :class => 'accept_tos'
      #   # => <input class="accept_tos" id="tos" name="tos" type="checkbox" value="yes" />
      #
      #   check_box_tag 'eula', 'accepted', false, :disabled => true
      #   # => <input disabled="disabled" id="eula" name="eula" type="checkbox" value="accepted" />
316
      def check_box_tag(name, value = "1", checked = false, options = {})
317
        html_options = { "type" => "checkbox", "name" => name, "id" => sanitize_to_id(name), "value" => value }.update(options.stringify_keys)
318
        html_options["checked"] = "checked" if checked
319
        tag :input, html_options
320 321
      end

322
      # Creates a radio button; use groups of radio buttons named the same to allow users to
323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340
      # select from a group of options.
      #
      # ==== Options
      # * <tt>:disabled</tt> - If set to true, the user will not be able to use this input.
      # * Any other key creates standard HTML options for the tag.
      #
      # ==== Examples
      #   radio_button_tag 'gender', 'male'
      #   # => <input id="gender_male" name="gender" type="radio" value="male" />
      #
      #   radio_button_tag 'receive_updates', 'no', true
      #   # => <input checked="checked" id="receive_updates_no" name="receive_updates" type="radio" value="no" />
      #
      #   radio_button_tag 'time_slot', "3:00 p.m.", false, :disabled => true
      #   # => <input disabled="disabled" id="time_slot_300_pm" name="time_slot" type="radio" value="3:00 p.m." />
      #
      #   radio_button_tag 'color', "green", true, :class => "color_input"
      #   # => <input checked="checked" class="color_input" id="color_green" name="color" type="radio" value="green" />
341
      def radio_button_tag(name, value, checked = false, options = {})
342
        html_options = { "type" => "radio", "name" => name, "id" => "#{sanitize_to_id(name)}_#{sanitize_to_id(value)}", "value" => value }.update(options.stringify_keys)
343
        html_options["checked"] = "checked" if checked
344
        tag :input, html_options
345 346
      end

347
      # Creates a submit button with the text <tt>value</tt> as the caption.
348 349
      #
      # ==== Options
S
Stefan Penner 已提交
350 351 352
      # * <tt>:confirm => 'question?'</tt> - If present the unobtrusive JavaScript 
      #   drivers will provide a prompt with the question specified. If the user accepts, 
      #   the form is processed normally, otherwise no action is taken.
P
Pratik Naik 已提交
353
      # * <tt>:disabled</tt> - If true, the user will not be able to use this input.
S
Stefan Penner 已提交
354 355 356
      # * <tt>:disable_with</tt> - Value of this parameter will be used as the value for a 
      #   disabled version of the submit button when the form is submitted. This feature is 
      #   provided by the unobtrusive JavaScript driver.
357 358 359 360 361 362 363 364 365 366 367 368
      # * Any other key creates standard HTML options for the tag.
      #
      # ==== Examples
      #   submit_tag
      #   # => <input name="commit" type="submit" value="Save changes" />
      #
      #   submit_tag "Edit this article"
      #   # => <input name="commit" type="submit" value="Edit this article" />
      #
      #   submit_tag "Save edits", :disabled => true
      #   # => <input disabled="disabled" name="commit" type="submit" value="Save edits" />
      #
S
Stefan Penner 已提交
369
      #
370
      #   submit_tag "Complete sale", :disable_with => "Please wait..."
S
Stefan Penner 已提交
371
      #   # => <input name="commit" data-disable-with="Please wait..."
372 373 374 375 376
      #   #    type="submit" value="Complete sale" />
      #
      #   submit_tag nil, :class => "form_submit"
      #   # => <input class="form_submit" name="commit" type="submit" />
      #
377
      #   submit_tag "Edit", :disable_with => "Editing...", :class => "edit-button"
S
Stefan Penner 已提交
378
      #   # => <input class="edit-button" data-disable_with="Editing..."
379
      #   #    name="commit" type="submit" value="Edit" />
S
Stefan Penner 已提交
380 381 382 383 384
      #
      #   submit_tag "Save", :confirm => "Are you sure?"
      #   # => <input name='commit' type='submit' value='Save' 
      #         data-confirm="Are you sure?" />
      #
385
      def submit_tag(value = "Save changes", options = {})
386
        options.stringify_keys!
387

388
        if disable_with = options.delete("disable_with")
389
          options["data-disable-with"] = disable_with if disable_with
390
        end
391

392
        if confirm = options.delete("confirm")
393
          add_confirm_to_attributes!(options, confirm)
394
        end
395

396
        tag :input, { "type" => "submit", "name" => "commit", "value" => value }.update(options.stringify_keys)
397
      end
398

399 400 401
      # Displays an image which when clicked will submit the form.
      #
      # <tt>source</tt> is passed to AssetTagHelper#image_path
402 403
      #
      # ==== Options
404 405 406
      # * <tt>:confirm => 'question?'</tt> - This will add a JavaScript confirm
      #   prompt with the question specified. If the user accepts, the form is
      #   processed normally, otherwise no action is taken.
407 408 409 410 411 412 413
      # * <tt>:disabled</tt> - If set to true, the user will not be able to use this input.
      # * Any other key creates standard HTML options for the tag.
      #
      # ==== Examples
      #   image_submit_tag("login.png")
      #   # => <input src="/images/login.png" type="image" />
      #
414
      #   image_submit_tag("purchase.png", :disabled => true)
415 416
      #   # => <input disabled="disabled" src="/images/purchase.png" type="image" />
      #
417
      #   image_submit_tag("search.png", :class => 'search-button')
418 419
      #   # => <input class="search-button" src="/images/search.png" type="image" />
      #
420
      #   image_submit_tag("agree.png", :disabled => true, :class => "agree-disagree-button")
421
      #   # => <input class="agree-disagree-button" disabled="disabled" src="/images/agree.png" type="image" />
422
      def image_submit_tag(source, options = {})
423 424 425
        options.stringify_keys!

        if confirm = options.delete("confirm")
426
          add_confirm_to_attributes!(options, confirm)
427 428
        end

429
        tag :input, { "type" => "image", "src" => path_to_image(source) }.update(options.stringify_keys)
430
      end
431 432 433 434

      # Creates a field set for grouping HTML form elements.
      #
      # <tt>legend</tt> will become the fieldset's title (optional as per W3C).
A
Andrew Kaspick 已提交
435
      # <tt>options</tt> accept the same values as tag.
436
      #
L
lifo 已提交
437
      # ==== Examples
438
      #   <%= field_set_tag do %>
439 440 441 442
      #     <p><%= text_field_tag 'name' %></p>
      #   <% end %>
      #   # => <fieldset><p><input id="name" name="name" type="text" /></p></fieldset>
      #
443
      #   <%= field_set_tag 'Your details' do %>
444 445 446
      #     <p><%= text_field_tag 'name' %></p>
      #   <% end %>
      #   # => <fieldset><legend>Your details</legend><p><input id="name" name="name" type="text" /></p></fieldset>
A
Andrew Kaspick 已提交
447
      #
448
      #   <%= field_set_tag nil, :class => 'format' do %>
A
Andrew Kaspick 已提交
449 450 451 452
      #     <p><%= text_field_tag 'name' %></p>
      #   <% end %>
      #   # => <fieldset class="format"><p><input id="name" name="name" type="text" /></p></fieldset>
      def field_set_tag(legend = nil, options = nil, &block)
453
        content = capture(&block)
W
wycats 已提交
454 455 456 457
        output = tag(:fieldset, options, true)
        output.safe_concat(content_tag(:legend, legend)) unless legend.blank?
        output.concat(content)
        output.safe_concat("</fieldset>")
458
      end
459

460 461 462 463 464
      private
        def html_options_for_form(url_for_options, options, *parameters_for_url)
          returning options.stringify_keys do |html_options|
            html_options["enctype"] = "multipart/form-data" if html_options.delete("multipart")
            html_options["action"]  = url_for(url_for_options, *parameters_for_url)
465
            html_options["data-remote"] = true if html_options.delete("remote")
466 467
          end
        end
468

469 470 471 472 473 474 475
        def extra_tags_for_form(html_options)
          case method = html_options.delete("method").to_s
            when /^get$/i # must be case-insentive, but can't use downcase as might be nil
              html_options["method"] = "get"
              ''
            when /^post$/i, "", nil
              html_options["method"] = "post"
476
              protect_against_forgery? ? content_tag(:div, token_tag, :style => 'margin:0;padding:0;display:inline') : ''
477 478
            else
              html_options["method"] = "post"
479
              content_tag(:div, tag(:input, :type => "hidden", :name => "_method", :value => method) + token_tag, :style => 'margin:0;padding:0;display:inline')
480 481
          end
        end
482

483 484
        def form_tag_html(html_options)
          extra_tags = extra_tags_for_form(html_options)
485
          (tag(:form, html_options, true) + extra_tags).html_safe
486
        end
487

488 489
        def form_tag_in_block(html_options, &block)
          content = capture(&block)
W
wycats 已提交
490 491 492 493
          output = ActiveSupport::SafeBuffer.new
          output.safe_concat(form_tag_html(html_options))
          output << content
          output.safe_concat("</form>")
494
        end
495 496

        def token_tag
497
          unless protect_against_forgery?
498 499
            ''
          else
500
            tag(:input, :type => "hidden", :name => request_forgery_protection_token.to_s, :value => form_authenticity_token)
501 502
          end
        end
503 504 505 506 507

        # see http://www.w3.org/TR/html4/types.html#type-name
        def sanitize_to_id(name)
          name.to_s.gsub(']','').gsub(/[^-a-zA-Z0-9:.]/, "_")
        end
508 509 510
    end
  end
end