From 3008963a4ba857efb808fa1d0a02cbac992a412c Mon Sep 17 00:00:00 2001 From: Tom Hughes Date: Thu, 22 Apr 2010 00:43:31 +0100 Subject: [PATCH] Case #2908: Escape user name in user not found error --- app/views/user/no_such_user.html.erb | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/app/views/user/no_such_user.html.erb b/app/views/user/no_such_user.html.erb index 585d29d8c..8507f5abb 100644 --- a/app/views/user/no_such_user.html.erb +++ b/app/views/user/no_such_user.html.erb @@ -1,2 +1,2 @@ -

<%= t 'user.no_such_user.heading', :user => @not_found_user %>

-

<%= t 'user.no_such_user.body', :user => @not_found_user %>

+

<%= t 'user.no_such_user.heading', :user => h(@not_found_user) %>

+

<%= t 'user.no_such_user.body', :user => h(@not_found_user) %>

-- 2.43.2