Add a bunch of fixes to HTML escaping, and a test case for it
[selectricity] / app / views / quickvote / thanks.rhtml
index 1975eb705162f592c259219e0143c87e4f046bcb..0fb3610028e2bc2bc78a39424539b367bdfff673 100644 (file)
@@ -5,7 +5,7 @@ preferences:</p>
 
 <ol>
   <% for rank in @voter.vote.rankings.sort %>
-    <li><%= rank.candidate.name.capitalize %> </li>
+    <li><%=h rank.candidate.name.capitalize %> </li>
   <% end %>
 </ol>
 

Benjamin Mako Hill || Want to submit a patch?