diff options
author | Jean-Philippe Lang <jp_lang@yahoo.fr> | 2017-10-12 17:36:21 +0000 |
---|---|---|
committer | Jean-Philippe Lang <jp_lang@yahoo.fr> | 2017-10-12 17:36:21 +0000 |
commit | 273dd9cb3bcfb1e0a0b90570b3b34eafa07d67aa (patch) | |
tree | fda3acf5a006f5bac0868b0c76a59ba2a0e6cf3e /app | |
parent | caca511d25ba607ab1bbb31658247d3d792e55b0 (diff) | |
download | redmine-273dd9cb3bcfb1e0a0b90570b3b34eafa07d67aa.tar.gz redmine-273dd9cb3bcfb1e0a0b90570b3b34eafa07d67aa.zip |
Don't use raw output (#27186).
git-svn-id: http://svn.redmine.org/redmine/trunk@16971 e93f8b46-1217-0410-a6f0-8f06a7374b81
Diffstat (limited to 'app')
-rw-r--r-- | app/views/issues/_list.html.erb | 4 |
1 files changed, 3 insertions, 1 deletions
diff --git a/app/views/issues/_list.html.erb b/app/views/issues/_list.html.erb index 5488fb295..8024a6948 100644 --- a/app/views/issues/_list.html.erb +++ b/app/views/issues/_list.html.erb @@ -31,7 +31,9 @@ <% end %> <tr id="issue-<%= issue.id %>" class="hascontextmenu <%= cycle('odd', 'even') %> <%= issue.css_classes %> <%= level > 0 ? "idnt idnt-#{level}" : nil %>"> <td class="checkbox hide-when-print"><%= check_box_tag("ids[]", issue.id, false, :id => nil) %></td> - <%= raw query.inline_columns.map {|column| "<td class=\"#{column.css_classes}\">#{column_content(column, issue)}</td>"}.join %> + <% query.inline_columns.each do |column| %> + <%= content_tag('td', column_content(column, issue), :class => column.css_classes) %> + <% end %> </tr> <% query.block_columns.each do |column| if (text = column_content(column, issue)) && text.present? -%> |