Add html_escape to project description. auto_link set description to html_safe but! dont escape html :(.

Signed-off-by: Dmitriy Zaporozhets <dmitriy.zaporozhets@gmail.com>
This commit is contained in:
Dmitriy Zaporozhets 2014-07-11 00:07:20 +03:00
parent a019b49a2b
commit 1218a5e630
No known key found for this signature in database
GPG Key ID: 627C5F589F467F17
1 changed files with 1 additions and 1 deletions

View File

@ -17,7 +17,7 @@
.col-md-7
.project-home-desc
- if @project.description.present?
= auto_link @project.description, link: :urls
= auto_link ERB::Util.html_escape(@project.description), link: :urls
- if can?(current_user, :admin_project, @project)
&ndash;
%strong= link_to 'Edit', edit_project_path