escape all passed params in js - fixes #2922

This commit is contained in:
Florian Staudacher 2012-02-24 14:09:54 +01:00
parent d54ff5f341
commit 663a5a0e7c

View file

@ -47,7 +47,7 @@
window.setTimeout(window.close, 2000, true);
});
var contents = "#{params[:title]} - #{params[:url]}";
var contents = "#{escape_javascript params[:title]} - #{escape_javascript params[:url]}";
var notes = "#{escape_javascript params[:notes]}";
if (notes.length > 0){
contents = contents + " - " + notes;