HTML.escape render_500

This commit is contained in:
Sdogruyol 2016-12-04 16:27:40 +03:00
parent 878c70e0d9
commit fa4573dcf9

View file

@ -22,7 +22,7 @@ end
def render_500(context, backtrace, verbosity)
message = if verbosity
"<pre>#{backtrace}</pre>"
"<pre><%= backtrace %></pre>"
else
"<p>Something wrong with the server :(</p>"
end
@ -42,7 +42,7 @@ def render_500(context, backtrace, verbosity)
</head>
<body>
<h2>Kemal has encountered an error. (500)</h2>
#{message}
<%= HTML.escape(message) %>
</body>
</html>
HTML