escape shit
This commit is contained in:
parent
5a8aed99ec
commit
50d27561e4
1 changed files with 3 additions and 1 deletions
|
@ -1,4 +1,6 @@
|
||||||
class DataTable
|
class DataTable
|
||||||
|
include ActionView::Helpers::JavaScriptHelper
|
||||||
|
include ERB::Util
|
||||||
def initialize user, params
|
def initialize user, params
|
||||||
@user = user
|
@user = user
|
||||||
@params = sanitize_params(params)
|
@params = sanitize_params(params)
|
||||||
|
@ -11,7 +13,7 @@ class DataTable
|
||||||
draw: @params[:draw],
|
draw: @params[:draw],
|
||||||
recordsTotal: @user.transactions.count,
|
recordsTotal: @user.transactions.count,
|
||||||
recordsFiltered: count,
|
recordsFiltered: count,
|
||||||
data: data
|
data: data.map { |d| (d["message"] = json_escape(d["message"])) && d }
|
||||||
}
|
}
|
||||||
end
|
end
|
||||||
private
|
private
|
||||||
|
|
Loading…
Reference in a new issue