From 4ec5b1600a9ebdfba4a1276b000513d71eaee16c Mon Sep 17 00:00:00 2001 From: Jean-Philippe Lang Date: Fri, 19 Dec 2008 10:16:15 +0000 Subject: Escape double-quotes in image titles. git-svn-id: svn+ssh://rubyforge.org/var/svn/redmine/trunk@2144 e93f8b46-1217-0410-a6f0-8f06a7374b81 --- lib/redcloth3.rb | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) (limited to 'lib/redcloth3.rb') diff --git a/lib/redcloth3.rb b/lib/redcloth3.rb index 7898d721f..fd56a8752 100644 --- a/lib/redcloth3.rb +++ b/lib/redcloth3.rb @@ -435,12 +435,15 @@ class RedCloth3 < String # # Flexible HTML escaping # - def htmlesc( str, mode ) + def htmlesc( str, mode=:Quotes ) + if str str.gsub!( '&', '&' ) str.gsub!( '"', '"' ) if mode != :NoQuotes str.gsub!( "'", ''' ) if mode == :Quotes str.gsub!( '<', '<') str.gsub!( '>', '>') + end + str end # Search and replace for Textile glyphs (quotes, dashes, other symbols) @@ -914,6 +917,7 @@ class RedCloth3 < String def inline_textile_image( text ) text.gsub!( IMAGE_RE ) do |m| stln,algn,atts,url,title,href,href_a1,href_a2 = $~[1..8] + htmlesc title atts = pba( atts ) atts = " src=\"#{ url }\"#{ atts }" atts << " title=\"#{ title }\"" if title -- cgit v1.2.3