contrib/opportunité: prevent useless xss exploit in meetup confirmation
authorAlexis Laferrière <alexis.laf@xymus.net>
Thu, 25 Jun 2015 20:33:18 +0000 (16:33 -0400)
committerAlexis Laferrière <alexis.laf@xymus.net>
Thu, 25 Jun 2015 20:36:22 +0000 (16:36 -0400)
Signed-off-by: Alexis Laferrière <alexis.laf@xymus.net>

contrib/opportunity/src/templates/meetup_confirmation.nit

index 648f4da..0194d76 100644 (file)
@@ -31,7 +31,7 @@ class MeetupConfirmation
                </div>
                <div class="container">
                        <div class="alert alert-success text-center" role="alert">
-                       {{{"Invite participants by sharing this link:"}}} <a href="./?meetup_id={{{meetup.id}}}">{{{meetup.name}}}</a>
+                       {{{"Invite participants by sharing this link:"}}} <a href="./?meetup_id={{{meetup.id}}}">{{{meetup.name.html_escape}}}</a>
                        </div>
                        <p class="text-center">
                        {{{"See you soon for more Opportunities!"}}}