Merge pull request #3556 from rense/master

format_html was missing in optional_logout template-tag
This commit is contained in:
José Padilla 2015-10-28 17:16:36 -04:00
commit a67d23139c

View File

@ -61,7 +61,8 @@ def optional_logout(request, user):
try:
logout_url = reverse('rest_framework:logout')
except NoReverseMatch:
return '<li class="navbar-text">{user}</li>'.format(user=user)
snippet = format_html('<li class="navbar-text">{user}</li>', user=escape(user))
return mark_safe(snippet)
snippet = """<li class="dropdown">
<a href="#" class="dropdown-toggle" data-toggle="dropdown">