Use html_escape method instead of gsub
This commit is contained in:
parent
7e79daf9af
commit
83b51875bb
|
@ -249,13 +249,7 @@ class Topic < ActiveRecord::Base
|
|||
end
|
||||
|
||||
def fancy_title
|
||||
sanitized_title = title.gsub(/['&\"<>]/, {
|
||||
"'" => ''',
|
||||
'&' => '&',
|
||||
'"' => '"',
|
||||
'<' => '<',
|
||||
'>' => '>',
|
||||
})
|
||||
sanitized_title = ERB::Util.html_escape(title)
|
||||
|
||||
return unless sanitized_title
|
||||
return sanitized_title unless SiteSetting.title_fancy_entities?
|
||||
|
|
Loading…
Reference in New Issue