Yet more escaping.
This commit is contained in:
parent
c5f93e3ea0
commit
789c6343d9
4 changed files with 8 additions and 8 deletions
|
@ -17,9 +17,9 @@
|
|||
<%= link_to_if trace.inserted?, 'map', {:controller => 'site', :action => 'index', :lat => trace.latitude, :lon => trace.longitude, :zoom => 14}, {:title => 'View Map'} %> /
|
||||
<%= link_to_if trace.inserted?, 'edit', {:controller => 'site', :action => 'edit', :lat => trace.latitude, :lon => trace.longitude, :zoom => 14, :gpx => trace.id }, {:title => 'Edit Map'} %>
|
||||
<br />
|
||||
<%= escape_once(trace.description) %>
|
||||
<%= h(trace.description) %>
|
||||
<br />
|
||||
by <%= link_to trace.user.display_name, {:controller => 'user', :action => 'view', :display_name => trace.user.display_name} %>
|
||||
by <%= link_to h(trace.user.display_name), {:controller => 'user', :action => 'view', :display_name => trace.user.display_name} %>
|
||||
in
|
||||
<% if trace.tags %>
|
||||
<% trace.tags.each do |tag| %>
|
||||
|
|
|
@ -1,4 +1,4 @@
|
|||
<h1><%= @title %></h1>
|
||||
<h1><%= h(@title) %></h1>
|
||||
|
||||
<span class="rsssmall"><a href="<%= url_for :action => 'georss', :display_name => @display_name, :tag => @tag %>"><img src="/images/RSS.gif" border="0" alt="RSS" /></a></span>
|
||||
<% if @user.nil? or @display_name.nil? or @user.display_name != @display_name %>
|
||||
|
|
|
@ -1,4 +1,4 @@
|
|||
<h2><%= @title %></h2>
|
||||
<h2><%= h(@title) %></h2>
|
||||
|
||||
<img src="<%= url_for :controller => 'trace', :action => 'picture', :id => @trace.id, :display_name => @trace.user.display_name %>">
|
||||
|
||||
|
@ -24,7 +24,7 @@
|
|||
<% end %>
|
||||
<tr>
|
||||
<td>Owner:</td>
|
||||
<td><%= link_to @trace.user.display_name, {:controller => 'user', :action => 'view', :display_name => @trace.user.display_name} %></td>
|
||||
<td><%= link_to h(@trace.user.display_name), {:controller => 'user', :action => 'view', :display_name => @trace.user.display_name} %></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Description:</td>
|
||||
|
|
|
@ -1,4 +1,4 @@
|
|||
<h2><%= @title %></h2>
|
||||
<h2><%= h(@title) %></h2>
|
||||
|
||||
<img src="<%= url_for :controller => 'trace', :action => 'picture', :id => @trace.id, :display_name => @trace.user.display_name %>">
|
||||
|
||||
|
@ -22,11 +22,11 @@
|
|||
<% end %>
|
||||
<tr>
|
||||
<td>Owner:</td>
|
||||
<td><%= link_to @trace.user.display_name, {:controller => 'user', :action => 'view', :display_name => @trace.user.display_name} %></td>
|
||||
<td><%= link_to g(@trace.user.display_name), {:controller => 'user', :action => 'view', :display_name => @trace.user.display_name} %></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Description:</td>
|
||||
<td><%= @trace.description %></td>
|
||||
<td><%= h(@trace.description) %></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Tags:</td>
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue