Sanitize dashboard action before displaying it
We were using `<%==`, which is the same as using `raw`. Note ERB Lint doesn't warn us of this usage. Brakeman does warn us, though.
This commit is contained in:
@@ -2,7 +2,7 @@
|
||||
|
||||
<div class="row expanded">
|
||||
<div class="small-12 medium-8 column">
|
||||
<%== dashboard_action.description %>
|
||||
<%= WYSIWYGSanitizer.new.sanitize(dashboard_action.description) %>
|
||||
<%= render "dashboard/form" %>
|
||||
</div>
|
||||
|
||||
|
||||
Reference in New Issue
Block a user