use escapeHtml

This commit is contained in:
Ashley //// 2024-04-11 08:21:04 +00:00
parent 5072d0e0b5
commit b30511af92

View file

@ -1604,7 +1604,7 @@ WIP! </a>
<% } %>
</h5>
<p class="comment" style="font-weight:700">
<%- x.content %><br><br>
<%- escapeHtml(x.content) %><br><br>
<% if (x.like_count === 0) { %><i class="fa-light fa-thumbs-up"></i> | <i class="fa-light fa-thumbs-down"></i>
<% } else { %><i class="fa-light fa-thumbs-up"></i>
<%= x.like_count %> | <i class="fa-light fa-thumbs-down"></i>