提交 fa4c7f76 编写于 作者: D Dmitriy Zaporozhets

Merge branch 'escape-before-autolink' into 'master'

Escape before autolink

Because auto_link set description to html_safe but dont escape html!!! :(

See merge request !963
......@@ -17,7 +17,7 @@
.col-md-7
.project-home-desc
- if @project.description.present?
= auto_link @project.description, link: :urls
= auto_link ERB::Util.html_escape(@project.description), link: :urls
- if can?(current_user, :admin_project, @project)
–
%strong= link_to 'Edit', edit_project_path
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册