FIX xss bug

This commit is contained in:
Jasder 2019-11-13 16:43:34 +08:00
parent d501415da4
commit 6c1a74240b
2 changed files with 3 additions and 3 deletions

View File

@ -5,7 +5,7 @@
<% if @project.description.blank? %> <% if @project.description.blank? %>
<p style="padding-top:5px;font-size:20px;font-weight:bold;"><%= @project.name %></p> <p style="padding-top:5px;font-size:20px;font-weight:bold;"><%= @project.name %></p>
<% else %> <% else %>
<p style="padding-top:5px"><%= h @project.description.html_safe %></p> <p style="padding-top:5px"><%= sanitize @project.description %></p>
<% end %> <% end %>
</div> </div>
</div> </div>
@ -40,4 +40,4 @@
</div> </div>
<script> <script>
autoUrl('project_description_code'); autoUrl('project_description_code');
</script> </script>

View File

@ -10,7 +10,7 @@
<span class="typeTag"><%= project.project_language&.name %></span> <span class="typeTag"><%= project.project_language&.name %></span>
</span> </span>
</p> </p>
<p class="c_grey02 f14"><%= project.description.html_safe %></p> <p class="c_grey02 f14"><%= sanitize project.description %></p>
</div> </div>
</li> </li>
<% end %> <% end %>