end
def options_id(value, values)
- values.collect { |f| "<option value='#{f.id}'" + (value.to_s == f.id.to_s ? " selected='selected'" : "") + ">#{f.name}</option>" }.to_s
+ values.collect { |f| "<option value='#{f.id}'" + (value.to_s == f.id.to_s ? " selected='selected'" : "") + ">#{h(f.name)}</option>" }.to_s
end
def options_key(value, values)
- values.collect { |f| "<option value='#{f.key}'" + (value.to_s == f.key ? " selected='selected'" : "") + ">#{f.name}</option>" }.to_s
+ values.collect { |f| "<option value='#{h(f.key)}'" + (value.to_s == f.key ? " selected='selected'" : "") + ">#{h(f.name)}</option>" }.to_s
end
def option_group(name, options)
- options.empty? ? '' : "<optgroup label=\"#{name}\">" + options + "</optgroup>"
+ options.empty? ? '' : "<optgroup label=\"#{h(name)}\">" + options + "</optgroup>"
end
end
<% if widget.properties_as_hash['filter'] and @filter %>
<div class="widget-title" id="widget_title_<%= widget.id -%>">
- <%= @filter.name -%>
+ <%= h @filter.name -%>
<% if @filter.period_index %>
- (<%= period_names[@filter.period_index-1] -%>)
+ (<%= h period_names[@filter.period_index-1] -%>)
<% end %>
</div>
<% elsif @dashboard.global and @resource and !widget.java_definition.global %>
- <div class="widget-title" id="widget_title_<%= widget.id -%>"><%= @resource.name -%></div>
+ <div class="widget-title" id="widget_title_<%= widget.id -%>"><%= h @resource.name -%></div>
<% end %>