require 'cgi' class CGI # Extends `#escape_html` to support escape modes. By default all strings # are escaped on `&`, `>` and `<`. Add the `:nonstandard` mode to omit # this conversion. # # If no mode is given then the `:default` mode is used. # # Available modes include: # * `:quote` - escapes single and double quotes # * `:newlines` - escapes newline characters (\r and \n) # * `:ampersand` - escapes the ampersand sign # * `:brackets` - escapes less-than and greater-than signs # * `:default` - escapes double quotes # # @example # escape_html("") #=> "<tag>" # escape_html("Example\nString", :newlines) #=> "Example String" # escape_html("\"QUOTE\"", false) #=> "\"QUOTE\"" # def self.escape_html(string, *modes) modes << :defualt if modes.empty? unless modes.include?(:nonstandard) string = string.gsub(/&/, '&').gsub(/>/, '>').gsub(//, '>').gsub(/