From ba5993ae79c49f12aaf28df0c849b7d6e7ef07df Mon Sep 17 00:00:00 2001 From: Robin Ward Date: Thu, 9 Jun 2016 15:10:21 -0400 Subject: [PATCH] FIX: Invalid escaping of URL --- app/views/users/omniauth_callbacks/complete.html.erb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/views/users/omniauth_callbacks/complete.html.erb b/app/views/users/omniauth_callbacks/complete.html.erb index c8517a29461..f1953307860 100644 --- a/app/views/users/omniauth_callbacks/complete.html.erb +++ b/app/views/users/omniauth_callbacks/complete.html.erb @@ -29,7 +29,7 @@ // On facebook browser, just redirect and don't close var ua = navigator.userAgent || navigator.vendor || window.opera; if ((ua.indexOf("FBAN") > -1) || (ua.indexOf("FBAV") > -1)) { - window.location.href = <%= Discourse.base_url.inspect %>; + window.location.href = '<%= Discourse.base_url.html_safe %>'; } else { window.close(); }