Use raw instead of html_safe
They do the exact same thing; however `html_safe` might confuse developers into thinking it will make the HTML safe. Using `raw` makes it clear that we're inserting the text without escaping it.
This commit is contained in:
@@ -11,10 +11,10 @@
|
||||
type: "image/png" %>
|
||||
<%= content_for :social_media_meta_tags %>
|
||||
|
||||
<%= setting["html.per_page_code_head"].try(:html_safe) %>
|
||||
<%= raw setting["html.per_page_code_head"] %>
|
||||
</head>
|
||||
<body class="<%= yield (:body_class) %>">
|
||||
<%= setting["html.per_page_code_body"].try(:html_safe) %>
|
||||
<%= raw setting["html.per_page_code_body"] %>
|
||||
|
||||
<h1 class="show-for-sr"><%= setting["org_name"] %></h1>
|
||||
|
||||
|
||||
Reference in New Issue
Block a user