In a Rails 3 application I have a domain class where one attribute stores pure HTML content (it\'s a blog app, the domain class is Post).
In the ERB templates, I ne
Using a double equals means the result is not escaped...
<%== somePost.content %>
See this SO question about it - What does <%== %> do in rails erb?
Use raw(string)
, as described in the release notes.
7.4.3 Other Changes
You no longer need to call h(string) to escape HTML output, it is on by default in all view templates. If you want the unescaped string, call raw(string).
Basically, where you did
<%=h @model.attr %>
before you can now use
<%= @model.attr %>
and where you did that before you can now use
<%=raw @model.attr %>
Try using raw(somePost.content)
. Alternatively, somePost.content.html_safe
.