various modifications to prevent xss
- validation of names and labels against /^[\w\s\'\-]*$/i - html entities encoding git-svn-id: http://redmine.rubyforge.org/svn/trunk@99 e93f8b46-1217-0410-a6f0-8f06a7374b81
This commit is contained in:
@@ -8,16 +8,6 @@
|
||||
|
||||
<% documents = @documents.group_by {|d| d.category } %>
|
||||
<% documents.each do |category, docs| %>
|
||||
<h3><%= category.name %></h3>
|
||||
<ul>
|
||||
<% docs.each do |d| %>
|
||||
<li>
|
||||
<b><%= link_to d.title, :controller => 'documents', :action => 'show', :id => d %></b>
|
||||
<br />
|
||||
<%= truncate d.description, 250 %><br />
|
||||
<em><%= format_time(d.created_on) %></em><br />
|
||||
</li>
|
||||
|
||||
<% end %>
|
||||
</ul>
|
||||
<h3><%= category.name %></h3>
|
||||
<%= render :partial => 'documents/document', :collection => docs %>
|
||||
<% end %>
|
||||
Reference in New Issue
Block a user