app/models/formstrap/thumbnail_view.rb in formstrap-0.3.1 vs app/models/formstrap/thumbnail_view.rb in formstrap-0.3.2

- old
+ new

@@ -90,13 +90,13 @@ def inline_svg(options = {}) blob.open do |file| content = file.read doc = Nokogiri::HTML::DocumentFragment.parse content - svg = doc.at_css 'svg' + svg = doc.at_css "svg" # for security - doc.search('script').each do |src| + doc.search("script").each do |src| src.remove end options.each { |attr, value| svg[attr.to_s] = value }