Make linkify return an HTML safe result for unsafe inputs

Fixes #2567
This commit is contained in:
Tom Hughes 2020-03-22 12:47:56 +00:00
parent 3184bec5ae
commit e693063fa5
2 changed files with 9 additions and 9 deletions

View file

@ -5,7 +5,7 @@ module ApplicationHelper
if text.html_safe?
Rinku.auto_link(text, :urls, tag_builder.tag_options(:rel => "nofollow")).html_safe
else
Rinku.auto_link(text, :urls, tag_builder.tag_options(:rel => "nofollow"))
Rinku.auto_link(ERB::Util.h(text), :urls, tag_builder.tag_options(:rel => "nofollow")).html_safe
end
end