cheap escape

This commit is contained in:
Konstantin Haase 2012-12-06 16:05:36 +01:00
parent 7b4fe5dab3
commit 24ea1ca7c0

View File

@ -433,7 +433,7 @@ if(window.parent == window) {
<body onload='document.forms[0].submit()'>
<form action="<%= uri %>" method='post'>
<input type='hidden' name='token' value='<%= token %>'>
<input type='hidden' name='user' value='<%= user.to_json %>'>
<input type='hidden' name='user' value="<%= user.to_json.gsub('"', '&quot;') %>">
<input type='hidden' name='storage' value='sessionStorage'>
</form>
</body>