Web Style Tweaks are CDATA
Make sure they're properly escaped.
This commit is contained in:
parent
9b7b6fb805
commit
ad620f63d3
2 changed files with 3 additions and 3 deletions
|
@ -69,7 +69,7 @@
|
|||
tags.</em>
|
||||
<br/>
|
||||
<textarea id="additionalStyle" class="disableAutoComplete" cols="50" rows="20"
|
||||
style="display:none" name="additional_style"><%= @web.additional_style %>
|
||||
style="display:none" name="additional_style"><%= h(@web.additional_style) %>
|
||||
</textarea>
|
||||
</div>
|
||||
|
||||
|
|
|
@ -26,10 +26,10 @@
|
|||
|
||||
<%= stylesheet_link_tag 'instiki' unless @inline_style %>
|
||||
|
||||
<style type="text/css">
|
||||
<style type="text/css"><!--/*--><![CDATA[/*><!--*/
|
||||
<%= @style_additions %>
|
||||
<%= @web ? @web.additional_style : '' %>
|
||||
</style>
|
||||
/*]]>*/--></style>
|
||||
<%= javascript_include_tag :defaults %>
|
||||
<% if @web %>
|
||||
<%= auto_discovery_link_tag(:atom, :controller => 'wiki', :web => @web.address, :action => 'atom_with_headlines') %>
|
||||
|
|
Loading…
Reference in a new issue