diff --git a/app/views/budgets/ballot/_ballot.html.erb b/app/views/budgets/ballot/_ballot.html.erb index fc5d9a128..c29a2b4f0 100644 --- a/app/views/budgets/ballot/_ballot.html.erb +++ b/app/views/budgets/ballot/_ballot.html.erb @@ -26,8 +26,8 @@

<%= group.name %> - <%= @ballot.heading_for_group(group).name %>

- <%= link_to t("budgets.ballots.show.remaining", - amount: @ballot.formatted_amount_available(@ballot.heading_for_group(group))).html_safe, + <%= link_to sanitize(t("budgets.ballots.show.remaining", + amount: @ballot.formatted_amount_available(@ballot.heading_for_group(group)))), budget_group_path(@budget, group) %> <% if @ballot.has_lines_in_group?(group) %> diff --git a/app/views/kaminari/_gap.html.erb b/app/views/kaminari/_gap.html.erb index fc2dbed0f..f5932a473 100644 --- a/app/views/kaminari/_gap.html.erb +++ b/app/views/kaminari/_gap.html.erb @@ -1,3 +1,3 @@ diff --git a/app/views/layouts/_flash.html.erb b/app/views/layouts/_flash.html.erb index a0f129224..6f881eeba 100644 --- a/app/views/layouts/_flash.html.erb +++ b/app/views/layouts/_flash.html.erb @@ -5,7 +5,7 @@
- <%= flash_message.try(:html_safe) %> + <%= sanitize(flash_message) %>