Commits on Nov 26, 2009
    Make sure strip_tags removes tags which start with a non-printable ch…

    Decode http_authentication creditentials without generating abitrary …

Commits on Nov 25, 2009
    Prepare for the 2.3.5 release

Commits on Nov 23, 2009
    Revert "Prefix Internet Explorer's accepted mime types with sensible …

    IE XHR requests are misinterpreted as HTML instead of JS.
    This reverts commit c680f23.
Commits on Nov 18, 2009
Commits on Nov 15, 2009
    Allow explicit placement of hidden id element for nested models.

    [#3259 state:resolved]
Commits on Nov 13, 2009
Commits on Nov 12, 2009
    Rdoc for changes introduced in 6339e5d, 542d6a0.

Commits on Nov 9, 2009
Commits on Nov 6, 2009
    Share ActionView::TestCase's output_buffer with view for concat support.

    [#3467 state:resolved]
Commits on Oct 28, 2009
    Make polymorphic_url work with symbols again and refactor it [#1384 s…

Commits on Oct 21, 2009
    Fixed HTTP digest to properly return 401 when the Authorization heade…

    …r has no nonce specified, or the Authorization header specifies Basic auth [#2968 state:resolved]
Commits on Oct 17, 2009
    Ensure number_to_human_size does not strip zeros from the end [#1763

Commits on Oct 15, 2009
Commits on Oct 14, 2009
    Make IntegrationTest::Runner propagate method_missing to ancestors.

    Fixes RSpec integration example groups, which mixes its Matchers
    module into ActiveSupport::TestCase.
    CookieJar#delete should return the key's value, consistent with a Hash

Commits on Oct 8, 2009
    Merge the prerequisites for on-by-default XSS escaping into rails.

    This consists of:
    * String#html_safe! a method to mark a string as 'safe'
    * ActionView::SafeBuffer a string subclass which escapes anything unsafe which is concatenated to it
    * Calls to String#html_safe! throughout the rails helpers
    * a 'raw' helper which lets you concatenate trusted HTML from non-safety-aware sources (e.g. presantized strings in the DB)
    Note, this does *not* give you on-by-default XSS escaping in 2.3 applications.  To get that you'll need to install a plugin:
Commits on Oct 7, 2009
    Explicitly require ActionController's CGI extensions so they're prope…

    …rly loaded before the first request.
Commits on Oct 6, 2009
Commits on Oct 5, 2009
Commits on Sep 28, 2009
    Introduce :almost keyword for distance_of_time_in_words. Make 1.75 da…

    …ys - 2 days return '2 days'.
    [#3266 state:committed]
