Skip to content

Commit 0af85cb

Browse files
committed
Escape HTML of supporters
fixes #171
1 parent 9f12ddb commit 0af85cb

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed

source/localizable/index.html.erb

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -20,19 +20,19 @@
2020
<ul class="supporters--list">
2121
<% (data.supporters.usergroups + data.supporters.conferences).each do |supporter| %>
2222
<li id="supporters--<%= supporter.name.downcase.gsub(/\W/, '_') %>" class="supporters--item">
23-
<h3 class="supporters--item-name"><%= supporter.name %></h3>
23+
<h3 class="supporters--item-name"><%=h supporter.name %></h3>
2424
<div class="user group">
25-
<span class="supporters--item-location"><%= supporter.city %>/<%= supporter.country %></span>
25+
<span class="supporters--item-location"><%=h supporter.city %>/<%=h supporter.country %></span>
2626
<%= link_to supporter.link.sub(%r(https?://), ''), supporter.link, class: 'supporters--item-link' %>
2727
<%= link_to('@' + supporter.twitter, 'https://twitter.com/' + supporter.twitter, class: 'supporters--item-link') unless supporter.twitter.blank? %>
2828
</div>
2929
<ul class="supporters--contacts">
3030
<% supporter.contacts.each do |contact| %>
3131
<li class="supporters--contacts-item">
32-
<%= contact.name %>
32+
<%=h contact.name %>
3333
<% %w(email phone).each do |medium| %>
3434
<% unless contact.send(medium).blank? %>
35-
<span class="supporters--contacts-item-<%= medium %>"><%= contact.send(medium) %></span>
35+
<span class="supporters--contacts-item-<%= medium %>"><%=h contact.send(medium) %></span>
3636
<% end %>
3737
<% end %>
3838
<%= link_to('@' + contact.twitter, 'https://twitter.com/' + contact.twitter, class: 'supporters--contacts-item-twitter') unless contact.twitter.blank? %>

0 commit comments

Comments
 (0)