From 6d8b0bbb9639037080b334487dccbe8f209ddd88 Mon Sep 17 00:00:00 2001 From: Dmitriy Zaporozhets <dmitriy.zaporozhets@gmail.com> Date: Thu, 31 Oct 2013 16:35:06 +0200 Subject: [PATCH] Correctly escape search query --- app/contexts/search_context.rb | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/app/contexts/search_context.rb b/app/contexts/search_context.rb index 742ab025a2..ec814c4dde 100644 --- a/app/contexts/search_context.rb +++ b/app/contexts/search_context.rb @@ -6,7 +6,8 @@ class SearchContext end def execute - query = Shellwords.shellescape(params[:search]) + query = params[:search] + query = Shellwords.shellescape(query) if query.present? return result unless query.present? -- 2.30.9