diff options
author | Jean-Philippe Lang <jp_lang@yahoo.fr> | 2009-10-25 13:28:36 +0000 |
---|---|---|
committer | Jean-Philippe Lang <jp_lang@yahoo.fr> | 2009-10-25 13:28:36 +0000 |
commit | 821f9eb390aa9a4be9909c8a276626eb6188fcdf (patch) | |
tree | 6b2019c500d1fb61c7c0eacda1d8e059f2676620 | |
parent | a3fcdfe3915173f28ea6001f1d250b9319b48ba1 (diff) | |
download | redmine-821f9eb390aa9a4be9909c8a276626eb6188fcdf.tar.gz redmine-821f9eb390aa9a4be9909c8a276626eb6188fcdf.zip |
HTML escaping (#4106).
git-svn-id: svn+ssh://rubyforge.org/var/svn/redmine/trunk@2979 e93f8b46-1217-0410-a6f0-8f06a7374b81
-rw-r--r-- | app/views/projects/settings/_versions.rhtml | 2 | ||||
-rw-r--r-- | app/views/roles/edit.rhtml | 2 |
2 files changed, 2 insertions, 2 deletions
diff --git a/app/views/projects/settings/_versions.rhtml b/app/views/projects/settings/_versions.rhtml index 79d92d81e..1f66dec43 100644 --- a/app/views/projects/settings/_versions.rhtml +++ b/app/views/projects/settings/_versions.rhtml @@ -14,7 +14,7 @@ <td><%= link_to h(version.name), :controller => 'versions', :action => 'show', :id => version %></td> <td align="center"><%= format_date(version.effective_date) %></td> <td><%=h version.description %></td> - <td><%= link_to(version.wiki_page_title, :controller => 'wiki', :page => Wiki.titleize(version.wiki_page_title)) unless version.wiki_page_title.blank? || @project.wiki.nil? %></td> + <td><%= link_to(h(version.wiki_page_title), :controller => 'wiki', :page => Wiki.titleize(version.wiki_page_title)) unless version.wiki_page_title.blank? || @project.wiki.nil? %></td> <td align="center"><%= link_to_if_authorized l(:button_edit), { :controller => 'versions', :action => 'edit', :id => version }, :class => 'icon icon-edit' %></td> <td align="center"><%= link_to_if_authorized l(:button_delete), {:controller => 'versions', :action => 'destroy', :id => version}, :confirm => l(:text_are_you_sure), :method => :post, :class => 'icon icon-del' %></td> </tr> diff --git a/app/views/roles/edit.rhtml b/app/views/roles/edit.rhtml index df3a4f320..61fcc633a 100644 --- a/app/views/roles/edit.rhtml +++ b/app/views/roles/edit.rhtml @@ -1,4 +1,4 @@ -<h2><%= link_to l(:label_role_plural), :controller => 'roles', :action => 'index' %> » <%= @role.name %></h2> +<h2><%= link_to l(:label_role_plural), :controller => 'roles', :action => 'index' %> » <%=h @role.name %></h2> <% labelled_tabular_form_for :role, @role, :url => { :action => 'edit' }, :html => {:id => 'role_form'} do |f| %> <%= render :partial => 'form', :locals => { :f => f } %> |