Friday, March 23, 2012

[Rails] pass iframe through sanitize

Hello,
I want to let users place in textfield an iframe tag from google maps.
Sanitize cuts everything. I want to  add some kind of rule to sanitize, so it cuts js, but pass through an iframe from google maps and yandex maps
Tried to place in  config config.action_view.sanitized_allowed_tags = %w('iframe') . It didn't help.
sample 
<iframe width="650" height="300" frameborder="0" scrolling="no" marginheight="0" marginwidth="0" src="http://maps.google.ru/maps/ms?hl=ru&amp;gl=ru&amp;ptab=2&amp;ie=UTF8&amp;oe=UTF8&amp;msa=0&amp;msid=217915074489641580339.0004929006f65793c1d47&amp;t=h&amp;source=embed&amp;ll=55.823209,37.8167&amp;spn=0.023998,0.037119&amp;output=embed"></iframe>

--
You received this message because you are subscribed to the Google Groups "Ruby on Rails: Talk" group.
To view this discussion on the web visit https://groups.google.com/d/msg/rubyonrails-talk/-/64WCQGWi180J.
To post to this group, send email to rubyonrails-talk@googlegroups.com.
To unsubscribe from this group, send email to rubyonrails-talk+unsubscribe@googlegroups.com.
For more options, visit this group at http://groups.google.com/group/rubyonrails-talk?hl=en.

0 Comments:

Post a Comment

Subscribe to Post Comments [Atom]

<< Home


Real Estate