X-Git-Url: https://git.openstreetmap.org/rails.git/blobdiff_plain/516aef5d07eaaad43311bc60018648b952d95a1d..2cbcabb3f6992904903a72dfbcef624bd391a314:/app/views/site/edit.rhtml diff --git a/app/views/site/edit.rhtml b/app/views/site/edit.rhtml index ceb4702d4..16c2ef3f2 100644 --- a/app/views/site/edit.rhtml +++ b/app/views/site/edit.rhtml @@ -6,6 +6,11 @@

The OpenStreetMap database is currently in read-only mode while essential database maintenance work is carried out.

+<% elsif !@user.data_public? %> +

You haven't set your edits to be public.

+

You can't use the online editor unless you do so. You can set your edits as public from your +<%= link_to 'user page', {:controller => 'user', :action => 'account', :display_name => @user.display_name}%>.

+

(Find out why this is the case.)

<% else %> <% content_for :greeting do %> <% if @user and !@user.home_lon.nil? and !@user.home_lat.nil? %> @@ -19,17 +24,17 @@ <% session[:token] = @user.tokens.create.token unless session[:token] %> <% if params['mlon'] and params['mlat'] %> -<% lon = params['mlon'] %> -<% lat = params['mlat'] %> -<% zoom = params['zoom'] || '12' %> +<% lon = h(params['mlon']) %> +<% lat = h(params['mlat']) %> +<% zoom = h(params['zoom']) || '12' %> <% elsif @user and params['lon'].nil? and params['lat'].nil? %> <% lon = @user.home_lon %> <% lat = @user.home_lat %> <% zoom = '12' %> <%else%> -<% lon = params['lon'] || '-0.1' %> -<% lat = params['lat'] || '51.5' %> -<% zoom = params['zoom'] || '12' %> +<% lon = h(params['lon']) || '-0.1' %> +<% lat = h(params['lat']) || '51.5' %> +<% zoom = h(params['zoom']) || '12' %> <% end %>
You need a Flash player to use Potlatch, the @@ -49,7 +54,9 @@ fo.addVariable('long',lon); fo.addVariable('scale',sc); fo.addVariable('token','<%= session[:token] %>'); -<% if params['gpx'] %> fo.addVariable('gpx','<%= params['gpx']+"/data" %>'); <% end %> + <% if params['gpx'] %> + fo.addVariable('gpx','<%= h(params['gpx']) + "/data" %>'); + <% end %> fo.write("map"); } @@ -90,5 +97,6 @@ window.onresize = handleResize; window.onload = handleResize; + <% end %>