escape all passed params in js - fixes #2922

This commit is contained in:
Florian Staudacher 2012-02-24 14:09:54 +01:00
parent d54ff5f341
commit 663a5a0e7c

View file

@ -47,7 +47,7 @@
window.setTimeout(window.close, 2000, true); window.setTimeout(window.close, 2000, true);
}); });
var contents = "#{params[:title]} - #{params[:url]}"; var contents = "#{escape_javascript params[:title]} - #{escape_javascript params[:url]}";
var notes = "#{escape_javascript params[:notes]}"; var notes = "#{escape_javascript params[:notes]}";
if (notes.length > 0){ if (notes.length > 0){
contents = contents + " - " + notes; contents = contents + " - " + notes;