1. 27 3月, 2010 1 次提交
  2. 15 3月, 2010 1 次提交
  3. 07 3月, 2010 1 次提交
    • W
      Make many parts of Rails lazy. In order to facilitate this, · 39d6f9e1
      wycats 提交于
      add lazy_load_hooks.rb, which allows us to declare code that
      should be run at some later time. For instance, this allows
      us to defer requiring ActiveRecord::Base at boot time purely
      to apply configuration. Instead, we register a hook that should
      apply configuration once ActiveRecord::Base is loaded.
      
      With these changes, brings down total boot time of a
      new app to 300ms in production and 400ms in dev.
      
      TODO: rename base_hook
      39d6f9e1
  4. 21 2月, 2010 1 次提交
  5. 15 2月, 2010 2 次提交
  6. 01 2月, 2010 1 次提交
    • Y
      For performance reasons, you can no longer call html_safe! on Strings.... · 4cbb9db0
      Yehuda Katz 提交于
      For performance reasons, you can no longer call html_safe! on Strings. Instead, all Strings are always not html_safe?. Instead, you can get a SafeBuffer from a String by calling #html_safe, which will SafeBuffer.new(self).
      
        * Additionally, instead of doing concat("</form>".html_safe), you can do
          safe_concat("</form>"), which will skip both the flag set, and the flag
          check.
        * For the first pass, I converted virtually all #html_safe!s to #html_safe,
          and the tests pass. A further optimization would be to try to use
          #safe_concat as much as possible, reducing the performance impact if
          we know up front that a String is safe.
      4cbb9db0
  7. 07 1月, 2010 1 次提交
  8. 22 10月, 2009 1 次提交
  9. 18 10月, 2009 1 次提交
  10. 08 10月, 2009 2 次提交
    • M
      error procs have to be safe too · c352ec06
      Michael Koziarski 提交于
      c352ec06
    • M
      Switch to on-by-default XSS escaping for rails. · 94159359
      Michael Koziarski 提交于
        This consists of:
      
        * String#html_safe! a method to mark a string as 'safe'
        * ActionView::SafeBuffer a string subclass which escapes anything unsafe which is concatenated to it
        * Calls to String#html_safe! throughout the rails helpers
        * a 'raw' helper which lets you concatenate trusted HTML from non-safety-aware sources (e.g. presantized strings in the DB)
        * New ERB implementation based on erubis which uses a SafeBuffer instead of a String
      
      Hat tip to Django for the inspiration.
      94159359
  11. 08 8月, 2009 1 次提交
  12. 29 7月, 2009 1 次提交
  13. 20 7月, 2009 1 次提交
  14. 19 7月, 2009 2 次提交
  15. 18 6月, 2009 1 次提交
  16. 09 6月, 2009 1 次提交
  17. 15 5月, 2009 1 次提交
  18. 05 4月, 2009 1 次提交
  19. 08 3月, 2009 1 次提交
  20. 03 9月, 2008 1 次提交
  21. 14 8月, 2008 1 次提交
  22. 28 7月, 2008 2 次提交
  23. 16 7月, 2008 1 次提交
  24. 08 7月, 2008 2 次提交
  25. 23 6月, 2008 1 次提交
  26. 22 6月, 2008 1 次提交
  27. 19 6月, 2008 1 次提交
  28. 05 6月, 2008 1 次提交
  29. 02 5月, 2008 1 次提交
  30. 29 3月, 2008 2 次提交
  31. 02 3月, 2008 1 次提交
  32. 12 1月, 2008 1 次提交
  33. 21 12月, 2007 1 次提交
  34. 26 10月, 2007 1 次提交