B.19. ERB::Util
B.19.1. active_support/core_ext/string/output_safety
html_escape(s)
A utility method for escaping HTML tag characters. This method is also aliased as h.
In your templates, use this method to escape any unsafe (often, anything user-submitted) content, like this:
You are currently reading a PREVIEW of this book.
Get instant access to over
$1 million worth of books and videos.
Start a Free Trial