fix #828, may cause unintentional break in other features, but security is no.1

This commit is contained in:
Unknwon 2015-01-20 13:08:49 +08:00
parent 0e286a0ca9
commit 8e384ce46c
7 changed files with 13 additions and 10 deletions

View file

@ -1 +1 @@
0.5.11.0103 Beta
0.5.12.0120 Beta

View file

@ -32,7 +32,7 @@
<a href="{{$.RepoLink}}/issues?milestone={{.Index}}{{if .IsClosed}}&state=closed{{end}}">Issues</a>
</p>
<hr/>
<p class="description">{{.RenderedContent | str2html}}</p>
<p class="description">{{.RenderedContent | Str2html}}</p>
</div>
{{end}}
</div>

View file

@ -25,7 +25,7 @@
<div class="panel panel-default issue-content">
<div class="panel-body">
<div class="content markdown">
{{str2html .Issue.RenderedContent}}
{{Str2html .Issue.RenderedContent}}
</div>
<div class="issue-edit-content hidden">
<div class="form-group">
@ -73,7 +73,7 @@
</div>
<div class="panel-body markdown">
{{if len .Content}}
{{str2html .Content}}
{{Str2html .Content}}
{{else}}
<i>No comment entered</i>
{{end}}

View file

@ -39,7 +39,7 @@
<span class="ahead">{{$.i18n.Tr "repo.release.ahead" .NumCommitsBehind .Target | Str2html}}</span>
</p>
<div class="markdown desc">
{{str2html .Note}}
{{Str2html .Note}}
</div>
<p class="download">
<a class="btn btn-gray btn-large btn-radius" href="{{$.RepoLink}}/archive/{{.TagName}}.zip" rel="nofollow"><i class="fa fa-download"></i> {{$.i18n.Tr "repo.release.source_code"}} (ZIP)</a>