<% end %>
<% if @user.home_lat.nil? or @user.home_lon.nil? %>
- <% lon = params['lon'] || '-0.1' %>
- <% lat = params['lat'] || '51.5' %>
- <% zoom = params['zoom'] || '4' %>
+ <% lon = h(params['lon'] || '-0.1') %>
+ <% lat = h(params['lat'] || '51.5') %>
+ <% zoom = h(params['zoom'] || '4') %>
<% else %>
- <% lon = @user.home_lon %>
- <% lat = @user.home_lat %>
- <% zoom = '12' %>
+ <% lon = @user.home_lon %>
+ <% lat = @user.home_lat %>
+ <% zoom = '12' %>
<% end %>
-<script type="text/javascript" src="/openlayers/OpenLayers.js"></script>
+<%= javascript_include_tag '/openlayers/OpenLayers.js' %>
+<%= javascript_include_tag '/openlayers/OpenStreetMap.js' %>
<%= javascript_include_tag 'map.js' %>
<script type="text/javascript">
window.onload = init;
// -->
-</script>
\ No newline at end of file
+</script>