Commit 056d42fc authored by Robert Lyon's avatar Robert Lyon

Bug 1719480: Need to escape displayname in elasticsearch templates

Change-Id: I663f6ffde03b6b3504d49a767ac0ff55d0ab8437
Signed-off-by: Robert Lyon's avatarRobert Lyon <robertl@catalyst.net.nz>
parent 648b191e
......@@ -52,7 +52,7 @@
</span>
{if $record->createdbyname}
<div class="createdby">
{str tag=createdby section=search.elasticsearch arg1='<a href="`$record->createdby|profile_url`">`$record->createdbyname|safe`</a>'}
{str tag=createdby section=search.elasticsearch arg1='<a href="`$record->createdby|profile_url`">`$record->createdbyname`</a>'}
</div>
{/if}
<div class="detail">
......
......@@ -18,7 +18,7 @@
{/if}
</span>
{if $record->createdbyname}
<div class="createdby">{str tag=createdby section=search.elasticsearch arg1='<a href="`$record->createdby|profile_url`">`$record->createdbyname|safe`</a>'}</div>
<div class="createdby">{str tag=createdby section=search.elasticsearch arg1='<a href="`$record->createdby|profile_url`">`$record->createdbyname`</a>'}</div>
{/if}
<div class="content-text">
{if $record->highlight}
......
......@@ -17,7 +17,7 @@
</h3>
<span class="artefacttype">({str tag=collection section=search.elasticsearch})</span>
{if $record->createdbyname}
<div class="createdby">{str tag=createdby section=search.elasticsearch arg1='<a href="`$record->createdby|profile_url`">`$record->createdbyname|safe`</a>'}</div>
<div class="createdby">{str tag=createdby section=search.elasticsearch arg1='<a href="`$record->createdby|profile_url`">`$record->createdbyname`</a>'}</div>
{/if}
<div class="detail">
{if $record->highlight}
......
......@@ -15,7 +15,7 @@
{if $record->anonymise}
{str tag=createdbyanon section=search.elasticsearch}
{else}
{str tag=createdby section=search.elasticsearch arg1='<a href="`$record->createdby|profile_url`">`$record->createdbyname|safe`</a>'}
{str tag=createdby section=search.elasticsearch arg1='<a href="`$record->createdby|profile_url`">`$record->createdbyname`</a>'}
{/if}
</div>
{/if}
......
......@@ -52,7 +52,7 @@
</span>
{if $record->createdbyname}
<div class="createdby">
{str tag=createdby section=search.elasticsearch arg1='<a href="`$record->createdby|profile_url`">`$record->createdbyname|safe`</a>'}
{str tag=createdby section=search.elasticsearch arg1='<a href="`$record->createdby|profile_url`">`$record->createdbyname`</a>'}
</div>
{/if}
<div class="detail">
......
......@@ -18,7 +18,7 @@
{/if}
</span>
{if $record->createdbyname}
<div class="createdby">{str tag=createdby section=search.elasticsearch arg1='<a href="`$record->createdby|profile_url`">`$record->createdbyname|safe`</a>'}</div>
<div class="createdby">{str tag=createdby section=search.elasticsearch arg1='<a href="`$record->createdby|profile_url`">`$record->createdbyname`</a>'}</div>
{/if}
<div class="content-text">{$record->description|str_shorten_html:100:true|safe}</div>
<!-- TAGS -->
......
......@@ -17,7 +17,7 @@
</h3>
<span class="artefacttype">({str tag=collection section=search.elasticsearch})</span>
{if $record->createdbyname}
<div class="createdby">{str tag=createdby section=search.elasticsearch arg1='<a href="`$record->createdby|profile_url`">`$record->createdbyname|safe`</a>'}</div>
<div class="createdby">{str tag=createdby section=search.elasticsearch arg1='<a href="`$record->createdby|profile_url`">`$record->createdbyname`</a>'}</div>
{/if}
<div class="detail">{$record->description|str_shorten_html:140:true|safe}</div>
<div class="tags"><strong>{str tag=pages section=search.elasticsearch}:</strong>
......
......@@ -15,7 +15,7 @@
{if $record->anonymise}
{str tag=createdbyanon section=search.elasticsearch}
{else}
{str tag=createdby section=search.elasticsearch arg1='<a href="`$record->createdby|profile_url`">`$record->createdbyname|safe`</a>'}
{str tag=createdby section=search.elasticsearch arg1='<a href="`$record->createdby|profile_url`">`$record->createdbyname`</a>'}
{/if}
</div>
{/if}
......
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment