From 876d0acb6b8ef23eb304a803c3cef0fc403ff08b Mon Sep 17 00:00:00 2001 From: Flavio Copes Date: Sun, 17 Jan 2016 20:52:05 +0100 Subject: [PATCH] Escape page titles --- themes/grav/templates/forms/fields/order/order.html.twig | 2 +- themes/grav/templates/pages.html.twig | 2 +- themes/grav/templates/partials/dashboard-pages.html.twig | 6 +++++- 3 files changed, 7 insertions(+), 3 deletions(-) diff --git a/themes/grav/templates/forms/fields/order/order.html.twig b/themes/grav/templates/forms/fields/order/order.html.twig index 7675912e..aad5b139 100644 --- a/themes/grav/templates/forms/fields/order/order.html.twig +++ b/themes/grav/templates/forms/fields/order/order.html.twig @@ -25,7 +25,7 @@ {% if siblings|length < 200 %} {% else %} diff --git a/themes/grav/templates/pages.html.twig b/themes/grav/templates/pages.html.twig index c803f94e..f508dd59 100644 --- a/themes/grav/templates/pages.html.twig +++ b/themes/grav/templates/pages.html.twig @@ -89,7 +89,7 @@ 0 ? 'data-toggle="children"' : ''}} data-hint="{{ description|trim(' • ') }}" class="hint--bottom"> - {{ p.title }} + {{ p.title|e }} {% if p.language %} {{p.language}} diff --git a/themes/grav/templates/partials/dashboard-pages.html.twig b/themes/grav/templates/partials/dashboard-pages.html.twig index 89cd08fe..8838fd8f 100644 --- a/themes/grav/templates/partials/dashboard-pages.html.twig +++ b/themes/grav/templates/partials/dashboard-pages.html.twig @@ -6,7 +6,11 @@

{{ "PLUGIN_ADMIN.LATEST_PAGE_UPDATES"|tu }}

{% for latest in admin.latestPages if admin.latestPages %} - + + + {% endfor %}
{{ latest.title }}{{ latest.route }}{{ latest.modified|nicetime }}
+ {{ latest.title|e }}{{ latest.route }}{{ latest.modified|nicetime }} +