diff --git a/app/views/events/index.rss.builder b/app/views/events/index.rss.builder index 0d3a6301..0c62f05b 100644 --- a/app/views/events/index.rss.builder +++ b/app/views/events/index.rss.builder @@ -34,7 +34,11 @@ xml.rdf :RDF, 'xmlns:rdf' => "http://www.w3.org/1999/02/22-rdf-syntax-ns#", content = render file: '/events/show.html', locals: { rss: true } xml.description strip_tags content - xml.content(:encoded) { xml.cdata! content.to_s } + xml.content(:encoded) { + xml.cdata! sanitize content, + tags: %w(p br table tr td ul ol li a strong b em i img), + attributes: %w(href src width height) + } end end end