Commits on May 28, 2012
  1. @tenderlove

    bumping to 3.0.13.rc1

    tenderlove authored
Commits on May 27, 2012
  1. @rafaelfranca
Commits on May 26, 2012
  1. @homakov

    do not force sanitize and whitelist protocols for auto_link

    homakov authored
    sanitize is not always required so we cannot make it. let's just
    whitelist protocols
Commits on May 25, 2012
  1. @homakov

    auto_link final sanitize

    homakov authored
Commits on Mar 27, 2012
  1. @tenderlove

    Merge pull request #5613 from carlosantoniodasilva/fix-build-3-0-193

    tenderlove authored
    Fix build for branch 3-0-stable - Ruby 1.9.3
  2. @josevalim @drogus

    Avoid inspecting the whole route set, closes #1525

    josevalim authored drogus committed
  3. @arunagw @carlosantoniodasilva

    Fix broken encoding test

    arunagw authored carlosantoniodasilva committed
  4. @tenderlove @carlosantoniodasilva
  5. @miloops @carlosantoniodasilva

    Use helper method here.

    miloops authored carlosantoniodasilva committed
  6. @miloops @carlosantoniodasilva
Commits on Mar 26, 2012
  1. @carlosantoniodasilva

    Fix AV::FixtureResolver and rjs tests with random order errors

    carlosantoniodasilva authored
    Due to the hash ordering changes on Ruby 1.8.7-p358.
Commits on Mar 24, 2012
  1. @arunagw @carlosantoniodasilva
Commits on Mar 15, 2012
  1. @tenderlove

    Merge pull request #5457 from brianmario/typo-fix

    tenderlove authored
    Fix typo in redirect test
  2. @tenderlove

    Merge pull request #5456 from brianmario/redirect-sanitization

    tenderlove authored
    Strip null bytes from Location header
Commits on Mar 7, 2012
  1. @arunagw
Commits on Mar 1, 2012
  1. @tenderlove

    bumping to 3.0.12

    tenderlove authored
  2. @tenderlove

    Merge branch '3-0-stable-security' into 3-0-12

    tenderlove authored
    * 3-0-stable-security:
      Ensure [] respects the status of the buffer.
      use AS::SafeBuffer#clone_empty for flushing the output_buffer
      add AS::SafeBuffer#clone_empty
      fix output safety issue with select options
Commits on Feb 22, 2012
  1. @tenderlove

    updating RAILS_VERSION

    tenderlove authored
  2. @jonleighton
Commits on Feb 21, 2012
  1. @amatsuda @tenderlove
Commits on Feb 20, 2012
  1. @lest @tenderlove

    fix output safety issue with select options

    lest authored tenderlove committed
Commits on Dec 31, 2011
  1. @amatsuda
Commits on Nov 19, 2011
  1. @jonleighton

    Don't html-escape the :count option to translate if it's a Numeric. F…

    jonleighton authored
    …ixes #3685.
Commits on Nov 18, 2011
  1. @jonleighton
Commits on Nov 17, 2011
  1. @lest @jonleighton

    _html translation should escape interpolated arguments

    lest authored jonleighton committed
  2. @jonleighton

    Implement a workaround for a bug in ruby-1.9.3p0.

    jonleighton authored
    The bug is that an error would be raised while attempting to convert a
    template from one encoding to another.
    Please see for more details.
    The workaround is to load all conversions into memory ahead of time,
    and will only happen if the ruby version is *exactly* 1.9.3p0. The
    hope is obviously that the underlying problem will be resolved in
    the next patchlevel release of 1.9.3.
Commits on Nov 16, 2011
  1. Added a missing parameter to relative_url_root= that was causing an A…

    mhuffnagle authored
    …rgumentError: wrong number of arguments (1 for 0) to be thrown at actionpack-3.0.10/lib/action_controller/railtie.rb:54.
Commits on Sep 27, 2011
  1. @parndt
Commits on Sep 11, 2011
  1. @misfo @jeremy

    prevent errors when passing a frozen string as a param to ActionContr…

    misfo authored jeremy committed
    since ActionDispatch::Http::Parameters#encode_params will force encoding on all params strings (when using an encoding aware Ruby), dup all strings passed into process.  This prevents modification of params passed in and, more importantly, doesn't barf when a frozen string is passed
    thanks and high fives to kinsteronline
Commits on Sep 8, 2011
  1. @guilleiguaran
  2. @akaspick
  3. @akaspick

    when calling url_for with a hash, additional (likely unwanted) values…

    akaspick authored
    … (such as :host) would be returned in the hash... calling #dup on the hash prevents this
Commits on Sep 7, 2011
  1. @akaspick
  2. @akaspick

    assert_select_email entry

    akaspick authored
  3. @akaspick

    fix assert_select_email to work on non-multipart emails as well as co…

    akaspick authored
    …nverting the Mail::Body to a string to prevent errors.
