Do some HTML escaping on election and candidate names
[selectricity-live] / app / views / election / edit_candidate.rhtml
index fe56aa08c37f3d20d8c33f03da7c2cef4442f181..7e1dd65704cd3ef9b33d7d59dd6be8ae36419587 100644 (file)
@@ -1,4 +1,4 @@
-<h1>Editing <%= @candidate.name %></h1>
+<h1>Editing <%=h @candidate.name %></h1>
 
 <%= error_messages_for :candidate %>
 <% form_tag( { :action => :update_candidate, :id => @candidate.id },

Benjamin Mako Hill || Want to submit a patch?