Closed paulschreiber closed 12 years ago
Subject lines are not HTML-escaped. If your subject line is
Hello <world>
You will see:
Hello
Here's the HTML letter_opener generates:
letter_opener
<dt>Subject:</dt> <dd><strong>Hello <world></strong></dd>
Looks like this is an easy fix in the erb:
<dt>Subject:</dt> <dd><strong><%= mail.subject %></strong></dd>
Change to:
<dt>Subject:</dt> <dd><strong><%= h mail.subject %></strong></dd>
Subject lines are not HTML-escaped. If your subject line is
You will see:
Here's the HTML
letter_opener
generates: