6 ms·
Twitter is probably still using Rails 2.3, where you have to explicitly tell the framework to html escape every time you're outputting a string. Rails 3 change
by dirtyhand 16y ago
Twitter is probably still using Rails 2.3, where you have to explicitly tell the framework to html escape every time you're outputting a string.
Rails 3 changes this by always html escaping strings.
- texec 16y agoSecurity shouldn't be a matter of the framework, especially if it belongs to well known problems like XSS.
- ashearer 16y agoWith programmers being human, there's a lot to be said for the framework providing a secure default. Even so, it's surprising how often this particular mistake occurs.
- marcinw 16y agoYou seriously think developers will manually HTML encode every time user input is rendered in the response? It's not just HTML they have to worry about, but Javascript, URL, HTML attributes, etc. If the framework doesn't automatically do it, nobody does it. That is, until they get hit by XSS.
- InclinedPlane 16y agoOf course. But there's no reason not to make security easier and more natural (pit of success vs. struggling uphill).
- wingo 16y agoDepends on what you mean by "framework". I would interpret that as "the language in which you write your application", and in that case a language that treats text and HTML as different datatypes does provide more security. Rails' conflation of these types guarantees that whatever the default for escaping, there will be bugs in applications written in/on rails.
- hnal943 16y agoI think twitter is using Lift, not Rails.
- fizx 16y agoNope