Escape HTML when displaying search results

This commit is contained in:
2017-05-31 17:14:14 +02:00
parent a806f294b2
commit d67f65019e
4 changed files with 10 additions and 8 deletions

View File

@@ -55,10 +55,10 @@ script(type="text/template", id="facet-template")
script(type="text/template", id="hit-template")
.search-hit.users(data-user-id='{{ objectID }}')
.search-hit-name
| {{{ _highlightResult.full_name.value }}}
small ({{{ username }}})
| {{ full_name }}
small ({{ username }})
.search-hit-roles
| {{{ roles }}}
| {{ roles }}
// Pagination template