From: Tom Hughes Date: Tue, 4 Mar 2008 17:57:51 +0000 (+0000) Subject: Yet more escaping. X-Git-Tag: live~7894 X-Git-Url: https://git.openstreetmap.org/rails.git/commitdiff_plain/789c6343d947da2cd38b20a70c08d4c116cea082 Yet more escaping. --- diff --git a/app/views/trace/_trace.rhtml b/app/views/trace/_trace.rhtml index 91862444a..095d66239 100644 --- a/app/views/trace/_trace.rhtml +++ b/app/views/trace/_trace.rhtml @@ -17,9 +17,9 @@ <%= link_to_if trace.inserted?, 'map', {:controller => 'site', :action => 'index', :lat => trace.latitude, :lon => trace.longitude, :zoom => 14}, {:title => 'View Map'} %> / <%= link_to_if trace.inserted?, 'edit', {:controller => 'site', :action => 'edit', :lat => trace.latitude, :lon => trace.longitude, :zoom => 14, :gpx => trace.id }, {:title => 'Edit Map'} %>
- <%= escape_once(trace.description) %> + <%= h(trace.description) %>
- by <%= link_to trace.user.display_name, {:controller => 'user', :action => 'view', :display_name => trace.user.display_name} %> + by <%= link_to h(trace.user.display_name), {:controller => 'user', :action => 'view', :display_name => trace.user.display_name} %> in <% if trace.tags %> <% trace.tags.each do |tag| %> diff --git a/app/views/trace/_trace_header.rhtml b/app/views/trace/_trace_header.rhtml index a9d8ca259..179b79c32 100644 --- a/app/views/trace/_trace_header.rhtml +++ b/app/views/trace/_trace_header.rhtml @@ -1,4 +1,4 @@ -

<%= @title %>

+

<%= h(@title) %>

RSS <% if @user.nil? or @display_name.nil? or @user.display_name != @display_name %> diff --git a/app/views/trace/edit.rhtml b/app/views/trace/edit.rhtml index 22405c1fc..d7c04182d 100644 --- a/app/views/trace/edit.rhtml +++ b/app/views/trace/edit.rhtml @@ -1,4 +1,4 @@ -

<%= @title %>

+

<%= h(@title) %>

@@ -24,7 +24,7 @@ <% end %> Owner: - <%= link_to @trace.user.display_name, {:controller => 'user', :action => 'view', :display_name => @trace.user.display_name} %> + <%= link_to h(@trace.user.display_name), {:controller => 'user', :action => 'view', :display_name => @trace.user.display_name} %> Description: diff --git a/app/views/trace/view.rhtml b/app/views/trace/view.rhtml index a5b0cef09..021b536e8 100644 --- a/app/views/trace/view.rhtml +++ b/app/views/trace/view.rhtml @@ -1,4 +1,4 @@ -

<%= @title %>

+

<%= h(@title) %>

@@ -22,11 +22,11 @@ <% end %> Owner: - <%= link_to @trace.user.display_name, {:controller => 'user', :action => 'view', :display_name => @trace.user.display_name} %> + <%= link_to g(@trace.user.display_name), {:controller => 'user', :action => 'view', :display_name => @trace.user.display_name} %> Description: - <%= @trace.description %> + <%= h(@trace.description) %> Tags: