Redmine/app/views/news/_news.rhtml
Jean-Philippe Lang 2b86ef8e28 various modifications to prevent xss
- validation of names and labels against /^[\w\s\'\-]*$/i
- html entities encoding

git-svn-id: http://redmine.rubyforge.org/svn/trunk@99 e93f8b46-1217-0410-a6f0-8f06a7374b81
2006-12-17 08:10:18 +00:00

5 lines
335 B
Plaintext

<p><%= link_to h(news.title), :controller => 'news', :action => 'show', :id => news %><br />
<% unless news.summary.empty? %><%=h news.summary %><br /><% end %>
<em><%= news.author.name %>, <%= format_time(news.created_on) %></em><br />
<%= news.comments_count %> <%= lwr(:label_comment, news.comments_count).downcase %><br /></p>