]> source.dussan.org Git - redmine.git/commitdiff
HTML escape at app/views/queries/index.rhtml.
authorToshi MARUYAMA <marutosijp2@yahoo.co.jp>
Tue, 2 Aug 2011 13:11:38 +0000 (13:11 +0000)
committerToshi MARUYAMA <marutosijp2@yahoo.co.jp>
Tue, 2 Aug 2011 13:11:38 +0000 (13:11 +0000)
git-svn-id: svn+ssh://rubyforge.org/var/svn/redmine/trunk@6381 e93f8b46-1217-0410-a6f0-8f06a7374b81

app/views/queries/index.rhtml

index 1c608b8acd571fd31d365279165d78a35a95c4f2..aa2a94a8456e439ccbd89f7a9bb31b19182cac20 100644 (file)
@@ -11,7 +11,7 @@
   <% @queries.each do |query| %>
     <tr class="<%= cycle('odd', 'even') %>">
       <td>
-        <%= link_to query.name, :controller => 'issues', :action => 'index', :project_id => @project, :query_id => query %>
+        <%= link_to h(query.name), :controller => 'issues', :action => 'index', :project_id => @project, :query_id => query %>
       </td>
       <td align="right">
         <small>