sanitize() flash messages

This commit is contained in:
cryptogopher 2023-04-05 23:25:50 +02:00
parent 803d9063d5
commit 155bf716e5

View File

@ -21,7 +21,7 @@
<div class="flashes"> <div class="flashes">
<% flash.each do |entry, message| %> <% flash.each do |entry, message| %>
<div class="flash <%= entry %>"> <div class="flash <%= entry %>">
<div><%= message %></div> <div><%= sanitize message %></div>
<button onclick="this.parentElement.style.display='none';">&times;</button> <button onclick="this.parentElement.style.display='none';">&times;</button>
</div> </div>
<% end %> <% end %>