HTML escape username

This commit is contained in:
Émilien Devos 2022-07-14 21:26:58 +00:00 committed by GitHub
parent 0ed22c0be0
commit 6c4ed282bb

View File

@ -68,7 +68,7 @@
</div> </div>
<% if env.get("preferences").as(Preferences).show_nick %> <% if env.get("preferences").as(Preferences).show_nick %>
<div class="pure-u-1-4"> <div class="pure-u-1-4">
<span id="user_name"><%= env.get("user").as(Invidious::User).email %></span> <span id="user_name"><%= HTML.escape(env.get("user").as(Invidious::User).email) %></span>
</div> </div>
<% end %> <% end %>
<div class="pure-u-1-4"> <div class="pure-u-1-4">