<div id="accordion-panel"></div>
<script type="text/javascript">
- window.fileKey = '<%= @file.key -%>';
- window.metric = '<%= @metric -%>';
+ window.fileKey = '<%= escape_javascript @file.key -%>';
+ window.metric = '<%= escape_javascript @metric -%>';
document.getElementById('crumbs').remove();
</script>
window.drilldown = {
metric: null,
- rule: <% if @rule %>'<%= @rule.key -%>'<% else %>null<% end %>,
- severity: <% if @severity %>'<%= @severity -%>'<% else %>null<% end %>,
- period: <% if @period %><%= @period -%><% else %>null<% end %>
+ rule: <% if @rule %>'<%= escape_javascript @rule.key -%>'<% else %>null<% end %>,
+ severity: <% if @severity %>'<%= escape_javascript @severity -%>'<% else %>null<% end %>,
+ period: <% if @period %><%= escape_javascript @period -%><% else %>null<% end %>
};
</script>
<div id="snapshot_title" class="page_title">
<h4>
<form method="GET" action="<%= url_for :action => 'measures' -%>" style="display: inline">
- <input type="hidden" name="metric" value="<%= params[:metric] -%>"/>
+ <input type="hidden" name="metric" value="<%= h params[:metric] -%>"/>
<select id="select-comparison" name="period" onchange="submit()">
<% if @drilldown.display_value? %>
<% end %>
window.drilldown = {
- metric: <% if @metric %>'<%= @metric.key -%>'<% else %>null<% end %>,
+ metric: <% if @metric %>'<%= escape_javascript @metric.key -%>'<% else %>null<% end %>,
rule: null,
severity: null,
- period: <% if @period %><%= @period -%><% else %>null<% end %>
+ period: <% if @period %><%= escape_javascript @period -%><% else %>null<% end %>
};
</script>