Escape input on friendy_name change.

This commit is contained in:
Tim 2015-12-06 14:39:50 +02:00
parent b0fa0d534e
commit e00c23bc49

View file

@ -115,7 +115,7 @@ DOCUMENTATION :: END
success: function(data) {
$("#edit-user-status-message").html(data);
if ($.trim(friendly_name) !== '') {
$(".set-username").html(friendly_name);
$('.set-username').html(document.createTextNode(friendly_name));
}
$("#user-profile-thumb").attr('src', thumb);
}