From 491c213af67ab65ea3f4b40e8cf39558fb378e6b Mon Sep 17 00:00:00 2001 From: Connor Shea Date: Tue, 21 Jun 2016 16:00:01 -0600 Subject: Fix unescaped strings in Underscore templates. --- app/assets/javascripts/issuable.js.coffee | 8 ++++---- app/assets/javascripts/labels_select.js.coffee | 6 +++--- app/assets/javascripts/milestone_select.js.coffee | 6 +++--- app/assets/javascripts/users_select.js.coffee | 12 ++++++------ 4 files changed, 16 insertions(+), 16 deletions(-) diff --git a/app/assets/javascripts/issuable.js.coffee b/app/assets/javascripts/issuable.js.coffee index 0527c66461c..c71d4ecf505 100644 --- a/app/assets/javascripts/issuable.js.coffee +++ b/app/assets/javascripts/issuable.js.coffee @@ -11,11 +11,11 @@ issuable_created = false initTemplates: -> Issuable.labelRow = _.template( '<% _.each(labels, function(label){ %> - - - <%= _.escape(label.title) %> + + + <%- label.title %> - diff --git a/app/assets/javascripts/labels_select.js.coffee b/app/assets/javascripts/labels_select.js.coffee index e95fd96a83f..ce859fedb2d 100644 --- a/app/assets/javascripts/labels_select.js.coffee +++ b/app/assets/javascripts/labels_select.js.coffee @@ -32,9 +32,9 @@ class @LabelsSelect if issueUpdateURL labelHTMLTemplate = _.template( '<% _.each(labels, function(label){ %> - issues?label_name[]=<%= _.escape(label.title) %>"> - - <%= _.escape(label.title) %> + issues?label_name[]=<%- label.title %>"> + + <%- label.title %> <% }); %>' diff --git a/app/assets/javascripts/milestone_select.js.coffee b/app/assets/javascripts/milestone_select.js.coffee index 02480f3a025..8ab03ed93ee 100644 --- a/app/assets/javascripts/milestone_select.js.coffee +++ b/app/assets/javascripts/milestone_select.js.coffee @@ -24,14 +24,14 @@ class @MilestoneSelect if issueUpdateURL milestoneLinkTemplate = _.template( - '<%= _.escape(title) %>' + '<%- title %>' ) milestoneLinkNoneTemplate = 'None' collapsedSidebarLabelTemplate = _.template( - ' - <%= _.escape(title) %> + ' + <%- title %> ' ) diff --git a/app/assets/javascripts/users_select.js.coffee b/app/assets/javascripts/users_select.js.coffee index 2548efb2186..4e032ab1ff1 100644 --- a/app/assets/javascripts/users_select.js.coffee +++ b/app/assets/javascripts/users_select.js.coffee @@ -61,8 +61,8 @@ class @UsersSelect collapsedAssigneeTemplate = _.template( '<% if( avatar ) { %> - - + + Toni Boehm <% } else { %> @@ -72,13 +72,13 @@ class @UsersSelect assigneeTemplate = _.template( '<% if (username) { %> - + <% if( avatar ) { %> - + <% } %> - <%= name %> + <%- name %> - @<%= username %> + @<%- username %> <% } else { %> -- cgit v1.2.1