Merge: contrib/opportunité: prevent useless xss exploit in meetup confirmation
authorJean Privat <jean@pryen.org>
Mon, 29 Jun 2015 12:21:02 +0000 (08:21 -0400)
committerJean Privat <jean@pryen.org>
Mon, 29 Jun 2015 12:21:02 +0000 (08:21 -0400)
Signed-off-by: Alexis Laferrière <alexis.laf@xymus.net>

Pull-Request: #1541
Reviewed-by: Jean-Philippe Caissy <jpcaissy@piji.ca>
Reviewed-by: Alexandre Terrasa <alexandre@moz-code.org>

contrib/opportunity/src/templates/meetup_confirmation.nit

index 648f4da..0194d76 100644 (file)
@@ -31,7 +31,7 @@ class MeetupConfirmation
                </div>
                <div class="container">
                        <div class="alert alert-success text-center" role="alert">
-                       {{{"Invite participants by sharing this link:"}}} <a href="./?meetup_id={{{meetup.id}}}">{{{meetup.name}}}</a>
+                       {{{"Invite participants by sharing this link:"}}} <a href="./?meetup_id={{{meetup.id}}}">{{{meetup.name.html_escape}}}</a>
                        </div>
                        <p class="text-center">
                        {{{"See you soon for more Opportunities!"}}}