Commits on Feb 22, 2012
  1. @tenderlove

    updating RAILS_VERSION

    tenderlove committed Feb 22, 2012
  2. @jonleighton
Commits on Nov 19, 2011
  1. @jonleighton

    Don't html-escape the :count option to translate if it's a Numeric. F…

    jonleighton committed Nov 19, 2011
    …ixes #3685.
Commits on Nov 18, 2011
  1. @jonleighton

    Preparing for 3.0.11 release

    jonleighton committed Nov 18, 2011
Commits on Nov 17, 2011
  1. @lest @jonleighton

    _html translation should escape interpolated arguments

    lest committed with jonleighton Nov 17, 2011
  2. @jonleighton

    Implement a workaround for a bug in ruby-1.9.3p0.

    jonleighton committed Nov 6, 2011
    The bug is that an error would be raised while attempting to convert a
    template from one encoding to another.
    Please see for more details.
    The workaround is to load all conversions into memory ahead of time,
    and will only happen if the ruby version is *exactly* 1.9.3p0. The
    hope is obviously that the underlying problem will be resolved in
    the next patchlevel release of 1.9.3.
Commits on Nov 16, 2011
  1. Added a missing parameter to relative_url_root= that was causing an A…

    mhuffnagle committed Nov 15, 2011
    …rgumentError: wrong number of arguments (1 for 0) to be thrown at actionpack-3.0.10/lib/action_controller/railtie.rb:54.
Commits on Sep 27, 2011
  1. @parndt
Commits on Sep 11, 2011
  1. @misfo @jeremy

    prevent errors when passing a frozen string as a param to ActionContr…

    misfo committed with jeremy Feb 8, 2011
    since ActionDispatch::Http::Parameters#encode_params will force encoding on all params strings (when using an encoding aware Ruby), dup all strings passed into process.  This prevents modification of params passed in and, more importantly, doesn't barf when a frozen string is passed
    thanks and high fives to kinsteronline
Commits on Sep 8, 2011
  1. @akaspick
  2. @akaspick

    when calling url_for with a hash, additional (likely unwanted) values…

    akaspick committed Aug 11, 2011
    … (such as :host) would be returned in the hash... calling #dup on the hash prevents this
Commits on Sep 7, 2011
  1. @akaspick

    fix assert_select_email to work on non-multipart emails as well as co…

    akaspick committed Aug 11, 2011
    …nverting the Mail::Body to a string to prevent errors.
Commits on Aug 31, 2011
  1. @tenderlove
Commits on Aug 16, 2011
  1. @tenderlove

    Merge branch '3-0-10' into 3-0-stable

    tenderlove committed Aug 16, 2011
    * 3-0-10:
      bumping rails to 3.0.10
      properly subsituting bad utf8 characters
      Tags with invalid names should also be stripped in order to prevent XSS attacks.  Thanks Sascha Depold for the report.
      prevent sql injection attacks by escaping quotes in column names
      Properly escape glob characters.
      bumping to 3.0.10.rc1
      more changelog updates
      updating CHANGELOGs
  2. @tenderlove

    bumping rails to 3.0.10

    tenderlove committed Aug 16, 2011
  3. @tenderlove

    Tags with invalid names should also be stripped in order to prevent

    tenderlove committed Aug 16, 2011
    XSS attacks.  Thanks Sascha Depold for the report.
  4. @tenderlove
Commits on Aug 11, 2011
  1. @spastorino

    Merge pull request #2494 from grzuy/3-0-stable

    spastorino committed Aug 11, 2011
    Porting changes on form_tag method signature to 3-0-stable
  2. @grzuy

    Remove 'parameters_for_url' from 'form_tag' method signature

    Gonzalo Rodriguez and Leonardo Capillera committed with grzuy Aug 11, 2011
Commits on Aug 5, 2011
  1. @tenderlove

    bumping to 3.0.10.rc1

    tenderlove committed Aug 4, 2011
  2. @fxn

    backports doc fix 9f9446f

    fxn committed Aug 5, 2011
Commits on Jul 24, 2011
  1. @spastorino

    Merge pull request #2080 from lhahne/3-0-stable

    spastorino committed Jul 23, 2011
    Fix improper detection and handling of html_safe buffer in CacheHelper
Commits on Jul 18, 2011
  1. @jstorimer

    Ensure that status codes are logged properly

    jstorimer committed Jul 18, 2011
    Needed to move AC::Metal::Instrumentation before AM::Metal::Rescue
    so that status codes rendered from rescue_from blocks are logged
Commits on Jul 17, 2011
  1. @lhahne

    made sure that the possible new output_buffer created by CacheHelper …

    lhahne committed Jul 17, 2011
    …is of the same type as the original
Commits on Jul 15, 2011
  1. @lhahne
Commits on Jul 1, 2011
  1. @bogdan @pixeltrix

    Fixed ActionView::FormOptionsHelper#select with :multiple => false

    bogdan committed with pixeltrix Jun 30, 2011
    (cherry picked from commit 0fdac01)
    Signed-off-by: Andrew White <>
Commits on Jun 29, 2011
  1. @guilleiguaran
Commits on Jun 23, 2011
  1. Fixes an issue where cache sweepers with only after filters would hav…

    Jeroen Jacobs committed Jun 21, 2011
    …e no controller object
    It would raise undefined method controller_name for nil
Commits on Jun 16, 2011
  1. @tenderlove

    Merge branch '3-0-9' into 3-0-stable

    tenderlove committed Jun 16, 2011
    * 3-0-9:
      Preparing for 3.0.9 release
      avoid false positives caused by release candidates
      Preparing for 3.0.9.rc5 release
      bumping to rc4
      Make sure that we don't perform in-place mutation on SafeBuffer string
      Update CHANGELOG to mention the json_escape change
      Ensure number helpers can handle HTML safe strings - closes #1597.
      bumping to rc3 since syck is not playing nicely
      bumping to 3.0.9.rc2
      ensuring that json_escape returns html safe strings when passed an html safe string
      Make sure `escape_javascript` return `SafeBuffer` if the incoming argument is already html_safe
      Fix issue #1598 by adding a dependency to the RDoc gem.
      bumping to 3.0.9.rc1
  2. @tenderlove

    Preparing for 3.0.9 release

    tenderlove committed Jun 16, 2011
Commits on Jun 15, 2011
  1. @dmathieu
  2. @dmathieu
  3. @dmathieu @pixeltrix

    simplify to only one condition

    dmathieu committed with pixeltrix Jun 15, 2011
    Signed-off-by: Andrew White <>
  4. @pixeltrix
Commits on Jun 12, 2011
  1. @tenderlove
