switch to using sanitize() instead of h() to escape message bodies. This is not quite as safe as there is no guarantee that the HTML scanner it uses will find everything, but is does allow benign HTML tags to be displayed again.
7 lines
609 B
Text
7 lines
609 B
Text
<% this_colour = cycle('lightgrey', 'white') # can only call once for some dumb reason %>
|
|
|
|
<tr class="inbox-row">
|
|
<td class="inbox-sender" bgcolor='<%= this_colour %>'><%= link_to sent_message_summary.recipient.display_name , :controller => 'user', :action => sent_message_summary.recipient.display_name %></td>
|
|
<td class="inbox-subject" bgcolor='<%= this_colour %>'><%= link_to h(sent_message_summary.title) , :controller => 'message', :action => 'read', :message_id => sent_message_summary.id %></td>
|
|
<td class="inbox-sent" bgcolor='<%= this_colour %>'><%= sent_message_summary.sent_on %></td>
|
|
</tr>
|