summaryrefslogtreecommitdiffstats
path: root/lib/redcloth3.rb
diff options
context:
space:
mode:
authorJean-Philippe Lang <jp_lang@yahoo.fr>2008-12-19 10:16:15 +0000
committerJean-Philippe Lang <jp_lang@yahoo.fr>2008-12-19 10:16:15 +0000
commit4ec5b1600a9ebdfba4a1276b000513d71eaee16c (patch)
treecba1428a84f575819cdcd96b8d44d6ac0bede335 /lib/redcloth3.rb
parent3ce1be14f7db2fcf6a2654a3ed5fe5c118119ec4 (diff)
downloadredmine-4ec5b1600a9ebdfba4a1276b000513d71eaee16c.tar.gz
redmine-4ec5b1600a9ebdfba4a1276b000513d71eaee16c.zip
Escape double-quotes in image titles.
git-svn-id: svn+ssh://rubyforge.org/var/svn/redmine/trunk@2144 e93f8b46-1217-0410-a6f0-8f06a7374b81
Diffstat (limited to 'lib/redcloth3.rb')
-rw-r--r--lib/redcloth3.rb6
1 files changed, 5 insertions, 1 deletions
diff --git a/lib/redcloth3.rb b/lib/redcloth3.rb
index 7898d721f..fd56a8752 100644
--- a/lib/redcloth3.rb
+++ b/lib/redcloth3.rb
@@ -435,12 +435,15 @@ class RedCloth3 < String
#
# Flexible HTML escaping
#
- def htmlesc( str, mode )
+ def htmlesc( str, mode=:Quotes )
+ if str
str.gsub!( '&', '&amp;' )
str.gsub!( '"', '&quot;' ) if mode != :NoQuotes
str.gsub!( "'", '&#039;' ) if mode == :Quotes
str.gsub!( '<', '&lt;')
str.gsub!( '>', '&gt;')
+ end
+ str
end
# Search and replace for Textile glyphs (quotes, dashes, other symbols)
@@ -914,6 +917,7 @@ class RedCloth3 < String
def inline_textile_image( text )
text.gsub!( IMAGE_RE ) do |m|
stln,algn,atts,url,title,href,href_a1,href_a2 = $~[1..8]
+ htmlesc title
atts = pba( atts )
atts = " src=\"#{ url }\"#{ atts }"
atts << " title=\"#{ title }\"" if title