3 common security issues in Rails


      tags = %w(a acronym b strong i em li ul ol h1 h2 h3 h4 h5 h6 \
      blockquote br cite sub sup ins p)
      s = sanitize(user_input, tags: tags, attributes: %w(href title))