From c12b96a89fcac14ca35f00cdd7a36a2994f111e3 Mon Sep 17 00:00:00 2001 From: Jean-Philippe Lang Date: Wed, 4 Nov 2009 10:11:47 +0000 Subject: [PATCH] Merged r2979 and r2980 from trunk. git-svn-id: svn+ssh://rubyforge.org/var/svn/redmine/branches/0.8-stable@2998 e93f8b46-1217-0410-a6f0-8f06a7374b81 --- app/controllers/issues_controller.rb | 4 ++++ app/views/projects/settings/_versions.rhtml | 2 +- app/views/roles/edit.rhtml | 2 +- 3 files changed, 6 insertions(+), 2 deletions(-) diff --git a/app/controllers/issues_controller.rb b/app/controllers/issues_controller.rb index 7f19fdf87..569d0c461 100644 --- a/app/controllers/issues_controller.rb +++ b/app/controllers/issues_controller.rb @@ -43,6 +43,10 @@ class IssuesController < ApplicationController helper :timelog include Redmine::Export::PDF + verify :method => :post, + :only => :destroy, + :render => { :nothing => true, :status => :method_not_allowed } + def index retrieve_query sort_init 'id', 'desc' diff --git a/app/views/projects/settings/_versions.rhtml b/app/views/projects/settings/_versions.rhtml index 79d92d81e..1f66dec43 100644 --- a/app/views/projects/settings/_versions.rhtml +++ b/app/views/projects/settings/_versions.rhtml @@ -14,7 +14,7 @@ <%= link_to h(version.name), :controller => 'versions', :action => 'show', :id => version %> <%= format_date(version.effective_date) %> <%=h version.description %> - <%= link_to(version.wiki_page_title, :controller => 'wiki', :page => Wiki.titleize(version.wiki_page_title)) unless version.wiki_page_title.blank? || @project.wiki.nil? %> + <%= link_to(h(version.wiki_page_title), :controller => 'wiki', :page => Wiki.titleize(version.wiki_page_title)) unless version.wiki_page_title.blank? || @project.wiki.nil? %> <%= link_to_if_authorized l(:button_edit), { :controller => 'versions', :action => 'edit', :id => version }, :class => 'icon icon-edit' %> <%= link_to_if_authorized l(:button_delete), {:controller => 'versions', :action => 'destroy', :id => version}, :confirm => l(:text_are_you_sure), :method => :post, :class => 'icon icon-del' %> diff --git a/app/views/roles/edit.rhtml b/app/views/roles/edit.rhtml index e53a0f545..b357cc985 100644 --- a/app/views/roles/edit.rhtml +++ b/app/views/roles/edit.rhtml @@ -1,4 +1,4 @@ -

<%=l(:label_role)%>: <%= @role.name %>

+

<%=l(:label_role)%>: <%=h @role.name %>

<% labelled_tabular_form_for :role, @role, :url => { :action => 'edit' }, :html => {:id => 'role_form'} do |f| %> <%= render :partial => 'form', :locals => { :f => f } %> -- 2.39.5