Skip to content

VYD-19575: Add custom plugin functionality and create sanitize plugin - #28

Merged
paulducsantos merged 6 commits into
masterfrom
add-sanitize-for-strings
Aug 31, 2026
Merged

paulducsantos merged 6 commits into
masterfrom
add-sanitize-for-strings

Conversation

@paulducsantos

@paulducsantos paulducsantos commented Aug 25, 2026 •

Copy link
Copy Markdown
Contributor

Created a Sanitize plugin that can sanitize strings
Use:

class MyForm < Gourami::Form
  plugin :sanitize

  attribute :content, :type => :sanitized_string
end

Also added custom plugin functionality. User's can now create their own plugin and use it in Form
Use:

ruby-dev >> module CustomPlugin
  module InstanceMethods
    def coerce_whatever(value, options = {})
      "whatever: #{value}"
    end
  end
end

ruby-dev >> class MyForm < Gourami::Form
  plugin(CustomPlugin)
    attribute :content, type: :whatever
end

ruby-dev >> form = MyForm.new(content: "Foo")
ruby-dev >> form.content
=> "whatever: Foo"

@paulducsantos paulducsantos changed the title add sanitize for strings VYD-19575: add sanitize for strings Aug 25, 2026
Comment thread lib/gourami/coercer.rb Outdated
# set_default_attribute_options at the gem level or consumer level.
value.strip! if options.fetch(:strip, true)
value.upcase! if options.fetch(:upcase, false)
value = Loofah.html4_fragment(value).scrub!(:prune).to_s if options.fetch(:sanitize, false)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

should we sanitize by default?

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

should we sanitize before we strip? if the input string is "<b>a</b> <script>x</script> " then after we sanitize we'd end up with "<b>a</b> " with a surviving trailing space.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice. Thanks Greg!

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nice catch, fixed

Comment thread lib/gourami/coercer.rb

@TSMMark TSMMark left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM But greg had some good feedback.

also we might consider making the coercers extensible so a user of this gem could add similar logic like this for their own project, without us having to add things like loofah as a gem dependency and add it to the base gem

@paulducsantos paulducsantos changed the title VYD-19575: add sanitize for strings VYD-19575: Add custom plugin functionality and create sanitize plugin Aug 28, 2026

@TSMMark TSMMark left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

magnifique! incroyable!

Comment thread lib/gourami/coercer.rb
value = send(:"coerce_#{type}", value, options) if type

if type
raise ":coerce_#{type} does not exist. Did you forget to add a plugin for :coerce_#{type}?" unless respond_to?(:"coerce_#{type}")

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧠

Comment thread lib/gourami/form.rb
# @param name [Symbol, Module] a name to look up under Gourami::Plugins
# (e.g. :sanitize loads gourami/plugins/sanitize and resolves
# Gourami::Plugins::Sanitize), or a Module to apply directly.
def self.plugin(name, *args, &block)

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

maybe we should leave a comment linking to the blog post about this @jeremyevans pattern

Comment thread spec/coercer_spec.rb
coercer.setter_filter(:name, "foo", :type => :whatever)
end

assert_equal(":coerce_whatever does not exist. Did you forget to add a plugin for :coerce_whatever?", error.message)

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nice!

Comment thread spec/form_spec.rb

describe Gourami::Form do
describe ".plugin" do
it "mixes in ClassMethods, InstanceMethods, and calls apply then configure" do

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

sick

@paulducsantos
paulducsantos merged commit 22d42c8 into master Aug 31, 2026
3 checks passed
@paulducsantos
paulducsantos deleted the add-sanitize-for-strings branch August 31, 2026 15:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants