]> source.dussan.org Git - redmine.git/commitdiff
HTML escape at app/views/issues/_list_simple.rhtml.
authorToshi MARUYAMA <marutosijp2@yahoo.co.jp>
Tue, 2 Aug 2011 13:03:51 +0000 (13:03 +0000)
committerToshi MARUYAMA <marutosijp2@yahoo.co.jp>
Tue, 2 Aug 2011 13:03:51 +0000 (13:03 +0000)
git-svn-id: svn+ssh://rubyforge.org/var/svn/redmine/trunk@6370 e93f8b46-1217-0410-a6f0-8f06a7374b81

app/views/issues/_list_simple.rhtml

index dd7f48946a2f31e2fc2b0728bf46b121b90209f6..1fcb07aeec8f943a22f3426de64cf1c183ed935b 100644 (file)
@@ -9,10 +9,10 @@
                </tr></thead>
                <tbody> 
                <% for issue in issues %>
-               <tr id="issue-<%= issue.id %>" class="hascontextmenu <%= cycle('odd', 'even') %> <%= issue.css_classes %>">
+               <tr id="issue-<%= h(issue.id) %>" class="hascontextmenu <%= cycle('odd', 'even') %> <%= issue.css_classes %>">
                        <td class="id">
                          <%= check_box_tag("ids[]", issue.id, false, :style => 'display:none;') %>
-                               <%= link_to issue.id, :controller => 'issues', :action => 'show', :id => issue %>
+                               <%= link_to(h(issue.id), :controller => 'issues', :action => 'show', :id => issue) %>
                        </td>
                        <td class="project"><%= link_to_project(issue.project) %></td>
                        <td class="tracker"><%=h issue.tracker %></td>