HTML escape username

This commit is contained in:
Émilien Devos 2022-07-14 21:26:58 +00:00 committed by GitHub
parent 0ed22c0be0
commit 6c4ed282bb

View File

@ -68,7 +68,7 @@
</div>
<% if env.get("preferences").as(Preferences).show_nick %>
<div class="pure-u-1-4">
<span id="user_name"><%= env.get("user").as(Invidious::User).email %></span>
<span id="user_name"><%= HTML.escape(env.get("user").as(Invidious::User).email) %></span>
</div>
<% end %>
<div class="pure-u-1-4">