Skip to content

Linter: Implement actionview-no-unnecessary-html-safe rule - #2007

Merged
marcoroth merged 1 commit into
mainfrom
actionview-no-unnecessary-html-safe
Aug 5, 2026
Merged

marcoroth merged 1 commit into
mainfrom
actionview-no-unnecessary-html-safe

Conversation

@marcoroth

@marcoroth marcoroth commented Aug 5, 2026 •

Copy link
Copy Markdown
Owner

This pull request implements a new actionview-no-unnecessary-html-safe rule that flags ERB output tags which consist of nothing but a String literal with .html_safe called on it.

<div <%= 'style="display: none;"'.html_safe %>></div>
Avoid calling `.html_safe` on the String literal `'style="display: none;"'`. Write the content directly in the template instead.

Resolves #1876

@github-actions github-actions Bot added documentation Improvements or additions to documentation linter @herb-tools/linter for HTML+ERB templates typescript TypeScript source across the javascript/ packages linter-rule Individual linter rules and their documentation linter-autofix Linter autofix behavior labels Aug 5, 2026
@marcoroth
marcoroth marked this pull request as ready for review August 5, 2026 02:32
@github-actions

github-actions Bot commented Aug 5, 2026 •

Copy link
Copy Markdown

🌿 Interactive Playground and Documentation Preview

A preview deployment has been built for this pull request. Try out the changes live in the interactive playground:


🌱 Grown from commit 96259ad


✅ Preview deployment has been cleaned up.

@pkg-pr-new

pkg-pr-new Bot commented Aug 5, 2026

Copy link
Copy Markdown
npx https://pkg.pr.new/@herb-tools/formatter@2007
npx https://pkg.pr.new/@herb-tools/language-server@2007
npx https://pkg.pr.new/@herb-tools/linter@2007

commit: 96259ad

@marcoroth
marcoroth merged commit ded671a into main Aug 5, 2026
22 checks passed
@marcoroth
marcoroth deleted the actionview-no-unnecessary-html-safe branch August 5, 2026 08:45
marcoroth added a commit that referenced this pull request Aug 5, 2026
Follow up on #2007.

`erb-no-unsafe-raw` flags every `.html_safe` call in an ERB output tag
with:

```
Avoid `.html_safe` in ERB output. It bypasses HTML escaping and can cause cross-site scripting (XSS) vulnerabilities.
```

That is not true when `.html_safe` is called directly on a String
literal. The content is static, so there is no value that escaping could
ever apply to and nothing that could carry injected input:

```html+erb
<div <%= 'style="display: none;"'.html_safe %>></div>
<p><%= "<strong>Sale</strong>".html_safe %></p>
```

Since #2007 those templates are already reported by
`actionview-no-unnecessary-html-safe`, which points out that the content
belongs in the template directly and offers an autocorrection for it.
Until now both rules reported the same tag and only one of the two
messages was accurate.

This pull request therefore makes `erb-no-unsafe-raw` skip `.html_safe`
calls whose receiver is a plain `StringNode`.

This branch was successfully deployed

1 active deployment
herb-tools (Preview) — 96259add Deployed Aug 5, 2026 by github-actions[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation linter @herb-tools/linter for HTML+ERB templates linter-autofix Linter autofix behavior linter-rule Individual linter rules and their documentation typescript TypeScript source across the javascript/ packages

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Linter: Calling .html_safe on String literals has no effect in ActionView

1 participant