summaryrefslogtreecommitdiffstats
path: root/app/views/attachments
diff options
context:
space:
mode:
authorToshi MARUYAMA <marutosijp2@yahoo.co.jp>2011-08-02 12:57:38 +0000
committerToshi MARUYAMA <marutosijp2@yahoo.co.jp>2011-08-02 12:57:38 +0000
commit7d2098bc22c7a9ecd12fe517d90f7c7f9c4a21cc (patch)
tree6683c6333b3fd3878744a9254e92dabbc5fe1745 /app/views/attachments
parent500b29d84cc966fa62d0f899ca25049d1dc30ccf (diff)
downloadredmine-7d2098bc22c7a9ecd12fe517d90f7c7f9c4a21cc.tar.gz
redmine-7d2098bc22c7a9ecd12fe517d90f7c7f9c4a21cc.zip
HTML escape at app/views/attachments/file.rhtml.
git-svn-id: svn+ssh://rubyforge.org/var/svn/redmine/trunk@6362 e93f8b46-1217-0410-a6f0-8f06a7374b81
Diffstat (limited to 'app/views/attachments')
-rw-r--r--app/views/attachments/file.rhtml4
1 files changed, 2 insertions, 2 deletions
diff --git a/app/views/attachments/file.rhtml b/app/views/attachments/file.rhtml
index c7e7a7573..fde551f8b 100644
--- a/app/views/attachments/file.rhtml
+++ b/app/views/attachments/file.rhtml
@@ -2,7 +2,7 @@
<div class="attachments">
<p><%= h("#{@attachment.description} - ") unless @attachment.description.blank? %>
- <span class="author"><%= @attachment.author %>, <%= format_time(@attachment.created_on) %></span></p>
+ <span class="author"><%= link_to_user(@attachment.author) %>, <%= format_time(@attachment.created_on) %></span></p>
<p><%= link_to_attachment @attachment, :text => l(:button_download), :download => true -%>
<span class="size">(<%= number_to_human_size @attachment.filesize %>)</span></p>
@@ -10,7 +10,7 @@
&nbsp;
<%= render :partial => 'common/file', :locals => {:content => @content, :filename => @attachment.filename} %>
-<% html_title @attachment.filename %>
+<% html_title h(@attachment.filename) %>
<% content_for :header_tags do -%>
<%= stylesheet_link_tag "scm" -%>