Commit c6af3919 authored by Richard Mansfield's avatar Richard Mansfield
Browse files

Escape notification subjects in inbox block


Signed-off-by: default avatarRichard Mansfield <richardm@catalyst.net.nz>
parent d388e75b
......@@ -5,8 +5,8 @@
<img src="{theme_url filename=cat('images/' $i.type '.gif')}" />
</td>
<td>
{if $i.url}<a href="{$i.url}">{/if}
{$i.subject}
{if $i.url}<a href="{$i.url|escape}">{/if}
{$i.subject|escape}
{if $i.url}</a>{/if}
</td>
</tr>
......
Supports Markdown
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment