Escape user names in diary views.
This commit is contained in:
parent
6c15eb7251
commit
cf8bd08a66
3 changed files with 3 additions and 3 deletions
|
@ -1,4 +1,4 @@
|
|||
<h2><%= @entry.user.display_name %>'s diary</h2>
|
||||
<h2><%= h(@entry.user.display_name) %>'s diary</h2>
|
||||
|
||||
<%= render :partial => 'diary_entry', :object => @entry %>
|
||||
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue