Brakeman Error - Unescaped model attribute near
问题 I am getting a lot error as follows Unescaped model attribute near line 20: show_errors(Objective.new(objective_params), :name) Expanded View This is my code module ApplicationHelper # Error Helper for Form def show_errors(object, field_name) if object.errors.any? && object.errors.messages[field_name][0].present? "<label class='text-error'>" + object.errors.messages[field_name][0] + "</label>" else return "" end end end 回答1: From Brakeman Cross Site Scripting docs: By default, Brakeman will