<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Acts As Suggest plugin</title>
	<atom:link href="http://programmingzen.com/2007/02/08/acts-as-suggest-plugin/feed/" rel="self" type="application/rss+xml" />
	<link>http://programmingzen.com/2007/02/08/acts-as-suggest-plugin/</link>
	<description>Meditations on programming, startups, and technology</description>
	<lastBuildDate>Thu, 10 May 2012 04:53:17 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: ittays</title>
		<link>http://programmingzen.com/2007/02/08/acts-as-suggest-plugin/#comment-179</link>
		<dc:creator>ittays</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://72.52.169.158/~antonioc/2007/02/08/acts-as-suggest-plugin/#comment-179</guid>
		<description>It&#039;s rarely known that if you follow your search with the word &#039;info&#039;, Google tries to snippet the Wiki information.</description>
		<content:encoded><![CDATA[<p>It&#8217;s rarely known that if you follow your search with the word &#8216;info&#8217;, Google tries to snippet the Wiki information.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Antonio Cangiano</title>
		<link>http://programmingzen.com/2007/02/08/acts-as-suggest-plugin/#comment-180</link>
		<dc:creator>Antonio Cangiano</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://72.52.169.158/~antonioc/2007/02/08/acts-as-suggest-plugin/#comment-180</guid>
		<description>Thanks ittays, that&#039;s a cool tip.</description>
		<content:encoded><![CDATA[<p>Thanks ittays, that&#8217;s a cool tip.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hsiu-Fan Wang</title>
		<link>http://programmingzen.com/2007/02/08/acts-as-suggest-plugin/#comment-181</link>
		<dc:creator>Hsiu-Fan Wang</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://72.52.169.158/~antonioc/2007/02/08/acts-as-suggest-plugin/#comment-181</guid>
		<description>Just wanted to post a comment to say this is totally awesome, despite the fact that no one else seems to have noticed :)</description>
		<content:encoded><![CDATA[<p>Just wanted to post a comment to say this is totally awesome, despite the fact that no one else seems to have noticed <img src='http://programmingzen.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zach Dennis</title>
		<link>http://programmingzen.com/2007/02/08/acts-as-suggest-plugin/#comment-182</link>
		<dc:creator>Zach Dennis</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://72.52.169.158/~antonioc/2007/02/08/acts-as-suggest-plugin/#comment-182</guid>
		<description>This is pretty sweet Antonio... I agree with Hsiu-fan. Great work!</description>
		<content:encoded><![CDATA[<p>This is pretty sweet Antonio&#8230; I agree with Hsiu-fan. Great work!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Benjamin Curtis</title>
		<link>http://programmingzen.com/2007/02/08/acts-as-suggest-plugin/#comment-183</link>
		<dc:creator>Benjamin Curtis</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://72.52.169.158/~antonioc/2007/02/08/acts-as-suggest-plugin/#comment-183</guid>
		<description>Posted at &lt;a href=&#039;http://www.agilewebdevelopment.com/plugins/acts_as_suggest&#039;&gt;agilewebdevelopment.com/plugins/acts_as_suggest&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Posted at <a href='http://www.agilewebdevelopment.com/plugins/acts_as_suggest'>agilewebdevelopment.com/plugins/acts_as_suggest</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Antonio Cangiano</title>
		<link>http://programmingzen.com/2007/02/08/acts-as-suggest-plugin/#comment-184</link>
		<dc:creator>Antonio Cangiano</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://72.52.169.158/~antonioc/2007/02/08/acts-as-suggest-plugin/#comment-184</guid>
		<description>Thanks Ben. Given the amount of interest, I&#039;ll work further on it. ;-)</description>
		<content:encoded><![CDATA[<p>Thanks Ben. Given the amount of interest, I&#8217;ll work further on it. <img src='http://programmingzen.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex Wayne</title>
		<link>http://programmingzen.com/2007/02/08/acts-as-suggest-plugin/#comment-185</link>
		<dc:creator>Alex Wayne</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://72.52.169.158/~antonioc/2007/02/08/acts-as-suggest-plugin/#comment-185</guid>
		<description>There is a bunch of code in the plugin that look ripe for SQL injection.

like:

&lt;typo:code lang=&quot;ruby&quot; class=&quot;small&quot;&gt;search_results = self.find(:all, :conditions =&gt; &quot;#{fields} = &#039;#{word}&#039;&quot;)&lt;/typo:code&gt;

That should be converted to this

&lt;typo:code lang=&quot;ruby&quot; class=&quot;small&quot;&gt;search_results = self.find(:all, :conditions =&gt; [&quot;#{fields} = ?&quot;, word])&lt;/typo:code&gt;

at the very least, since @word@ will probably be defined by some random user.  Also the building of the conditions query when there is more than 1 column needs to updated to fit that method as well.

Seems like a nifty plugin though!  I&#039;ll keep an eye on it.  Probably gonna put it to use in our search on &quot;MagneticWorld&quot;:http://magneticworld.com soon.</description>
		<content:encoded><![CDATA[<p>There is a bunch of code in the plugin that look ripe for SQL injection.</p>
<p>like:</p>
<p><typo:code lang="ruby" class="small">search_results = self.find(:all, :conditions => &#8220;#{fields} = &#8216;#{word}&#8217;&#8221;)</typo:code></p>
<p>That should be converted to this</p>
<p><typo:code lang="ruby" class="small">search_results = self.find(:all, :conditions => ["#{fields} = ?", word])</typo:code></p>
<p>at the very least, since @word@ will probably be defined by some random user.  Also the building of the conditions query when there is more than 1 column needs to updated to fit that method as well.</p>
<p>Seems like a nifty plugin though!  I&#8217;ll keep an eye on it.  Probably gonna put it to use in our search on &#8220;MagneticWorld&#8221;:<a href="http://magneticworld.com" rel="nofollow">http://magneticworld.com</a> soon.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Antonio Cangiano</title>
		<link>http://programmingzen.com/2007/02/08/acts-as-suggest-plugin/#comment-186</link>
		<dc:creator>Antonio Cangiano</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://72.52.169.158/~antonioc/2007/02/08/acts-as-suggest-plugin/#comment-186</guid>
		<description>You&#039;re obviously right Alex, I&#039;ve fixed that.</description>
		<content:encoded><![CDATA[<p>You&#8217;re obviously right Alex, I&#8217;ve fixed that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Arash</title>
		<link>http://programmingzen.com/2007/02/08/acts-as-suggest-plugin/#comment-187</link>
		<dc:creator>Arash</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://72.52.169.158/~antonioc/2007/02/08/acts-as-suggest-plugin/#comment-187</guid>
		<description>Will this be able to suggest based on another index, such as a ferret index?</description>
		<content:encoded><![CDATA[<p>Will this be able to suggest based on another index, such as a ferret index?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Antonio Cangiano</title>
		<link>http://programmingzen.com/2007/02/08/acts-as-suggest-plugin/#comment-188</link>
		<dc:creator>Antonio Cangiano</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://72.52.169.158/~antonioc/2007/02/08/acts-as-suggest-plugin/#comment-188</guid>
		<description>Hi Arash,

I plan to move this plugin to rubyforge soon. At that point, I&#039;ll work on expanding it to support further options, like Ferret.</description>
		<content:encoded><![CDATA[<p>Hi Arash,</p>
<p>I plan to move this plugin to rubyforge soon. At that point, I&#8217;ll work on expanding it to support further options, like Ferret.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

