Files
grecia/app/views/users/registrations/success.html.erb
Javi Martín 6b1864fbcd Sanitize translations instead of using _html
Using the `_html` suffix in an i18n key is the same as using `html_safe`
on it, which means that translation could potentially be used for XSS
attacks.
2019-10-09 19:46:47 +02:00

9 lines
448 B
Plaintext

<h2><%= t("devise_views.users.registrations.success.title") %></h2>
<p><%= sanitize(t("devise_views.users.registrations.success.thank_you")) %></p>
<p><%= sanitize(t("devise_views.users.registrations.success.instructions_1")) %></p>
<p><%= t("devise_views.users.registrations.success.instructions_2") %></p>
<p>
<%= link_to t("devise_views.users.registrations.success.back_to_index"),
root_path, class: "button margin-top expanded" %>
</p>