Rails 3.0 comes with XSS protection
After two years of development and 1600 contributors, Rails 3.0 has been released.
The internet is a scary place and Rails 3 is watching out for you by default. Rails had CRSF protection with form signing for a while and SQL-injection protection since the beginning, but Rails 3 ups the anté with XSS protection as well.
Watch the video below for more information: