From dc1dc4551982847eb9fc145791b3fd3ccdcf46e0 Mon Sep 17 00:00:00 2001 From: Evgeny Fadeev Date: Mon, 15 Apr 2013 16:14:54 -0400 Subject: fixed a bug with unescaped user name in head js --- askbot/templates/meta/html_head_javascript.html | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/askbot/templates/meta/html_head_javascript.html b/askbot/templates/meta/html_head_javascript.html index 965dd350..5d73d175 100644 --- a/askbot/templates/meta/html_head_javascript.html +++ b/askbot/templates/meta/html_head_javascript.html @@ -6,7 +6,7 @@ askbot['data']['languageCode'] = '{{ current_language_code }}'; {% if request.user.is_authenticated() %} askbot['data']['userId'] = {{ request.user.id }}; - askbot['data']['userName'] = '{{ request.user.username }}'; + askbot['data']['userName'] = '{{ request.user.username|escape }}'; askbot['data']['userIsAdminOrMod'] = {{ request.user.is_administrator()|as_js_bool }}; askbot['data']['userIsAdmin'] = {{ request.user.is_administrator()|as_js_bool }}; askbot['data']['userReputation'] = {{ request.user.reputation }}; -- cgit v1.2.3-1-g7c22