summaryrefslogtreecommitdiff
path: root/app/Template/board
diff options
context:
space:
mode:
authorFrancois Ferrand <thetypz@gmail.com>2015-03-04 17:03:04 +0100
committerFrancois Ferrand <thetypz@gmail.com>2015-03-04 17:03:38 +0100
commit6696484bd0082c230f91815229f2382e26a5d235 (patch)
treec9ea246860f70cd96fe2e3016e630d56766de6ea /app/Template/board
parent23f8f2c576271a9007b5da0a4d0ba144ad66086d (diff)
Escape markdown code in column tooltips.
This is needed to avoid issues when the code contains quotes.
Diffstat (limited to 'app/Template/board')
-rw-r--r--app/Template/board/edit.php2
-rw-r--r--app/Template/board/swimlane.php2
2 files changed, 2 insertions, 2 deletions
diff --git a/app/Template/board/edit.php b/app/Template/board/edit.php
index cf0c28e6..a6df1000 100644
--- a/app/Template/board/edit.php
+++ b/app/Template/board/edit.php
@@ -13,7 +13,7 @@
<tr>
<td class="column-60"><?= $this->e($column['title']) ?>
<?php if (! empty($column['description'])): ?>
- <span class="column-tooltip" title='<?= $this->markdown($column['description']) ?>'>
+ <span class="column-tooltip" title='<?= $this->e($this->markdown($column['description'])) ?>'>
<i class="fa fa-info-circle"></i>
</span>
<?php endif ?>
diff --git a/app/Template/board/swimlane.php b/app/Template/board/swimlane.php
index 4be92e58..744610ab 100644
--- a/app/Template/board/swimlane.php
+++ b/app/Template/board/swimlane.php
@@ -28,7 +28,7 @@
<?= $this->e($column['title']) ?>
<?php if (! empty($column['description'])): ?>
- <span class="column-tooltip pull-right" title='<?= $this->markdown($column['description']) ?>'>
+ <span class="column-tooltip pull-right" title='<?= $this->e($this->markdown($column['description'])) ?>'>
<i class="fa fa-info-circle"></i>
</span>
<?php endif ?>