|
@@ -30,7 +30,9 @@ pub async fn render(db: &DbClient, user: &str) -> String {
|
|
|
.unwrap_or(¬ification.origin_url)
|
|
|
.replace('&', "&")
|
|
|
.replace('<', "<")
|
|
|
- .replace('>', ">"),
|
|
|
+ .replace('>', ">")
|
|
|
+ .replace('"', """)
|
|
|
+ .replace('\'', "'"),
|
|
|
));
|
|
|
if let Some(metadata) = ¬ification.metadata {
|
|
|
out.push_str(&format!(
|
|
@@ -38,7 +40,9 @@ pub async fn render(db: &DbClient, user: &str) -> String {
|
|
|
metadata
|
|
|
.replace('&', "&")
|
|
|
.replace('<', "<")
|
|
|
- .replace('>', ">"),
|
|
|
+ .replace('>', ">")
|
|
|
+ .replace('"', """)
|
|
|
+ .replace('\'', "'"),
|
|
|
));
|
|
|
}
|
|
|
out.push_str("</li>");
|